Hi, guys
I created several dynamic watchlists quiring AD for “users with passwords never expired”.
The query works fine and I’m getting the watchlists filled in.
The question is, how to create a correlation rule that will trigger when new username added to the watchlist?
Solved! Go to Solution.
Hi, for new users just create an alarm for:
Signature ID = 43-263047380
Event_Class = Don't Expire Password - Enabled
Enjoy 🙂
Best Regards 👍👍👍
David
Not that I can think of - correlation rules are designed to bring together the behaviour of multiple events. You could correlate events that occur against the watchlist or have a historical ACE which is set up to run a correlation rule using the watchlist and looking back through events for 1-2 days/weeks whatever the need is.
Adding to a watchlist is not in itself an event. You could correlate the events where the users are created or modified?
yes, I can.
but these events realy tricky to parse for only this parameter...
Hi, for new users just create an alarm for:
Signature ID = 43-263047380
Event_Class = Don't Expire Password - Enabled
Enjoy 🙂
Best Regards 👍👍👍
David
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA