创建登录成功监控项:
键值:
eventlog[Security,,"Failure Audit",,^4625$,,skip]
创建登录失败监控项:
键值:
eventlog[Security,,"Success Audit",,^4624$,,skip]
创建特定账户登录成功的触发器:
表达式:
{PSDC01:eventlog[Security,,"Success Audit",,^4624$,,skip].nodata(60)}=0 and
{PSDC01:eventlog[Security,,"Success Audit",,^4624$,,skip].regexp(user1|user2|user3|Administrator|user4|user5)}=1
创建特定账户登录失败的触发器:
表达式:
{PSDC01:eventlog[Security,,"Failure Audit",,^4625$,,skip].nodata(60)}=0 and {PSDC01:eventlog[Security,,"Failure Audit",,^4625$,,skip].regexp(user1|user2|user3|Administrator|user4|user5)}=1
又或者想要监控所有用户的登录成功的触发器表达式:
{PSDC01:eventlog[Security,,"Success Audit",,^4624$,,skip].nodata(60)}=0 and
{PSDC01:eventlog[Security,,"Success Audit",,^4624$,,skip].str(Advapi)}=0
监控所有用户的登录失败的触发器表达式:
{PSDC01:eventlog[Security,,"Failure Audit",,^6281$,,skip].nodata(60)}=0 and {PSDC01:eventlog[Security,,"Failure Audit",,^6281$,,skip].str(Advapi)}=0