Security Compliance
SEM Rule to Disable Local User Account
This article provides steps on how to configure a SEM rule to disable local user account on agent nodes (Windows) for a "UserLogonFailure" event. This method can be used to add "Disable local user account" action.
First published date
Last published date
Overview
Product section
Cause
Resolution
Pre-requisites:
- SEM agent should be installed on the node and SEM is receiving the events from the node(s).
- "Windows Active Response" connector should be added and running on the node(s).
- User account should be available on the agent node.
A) Creating the base rule:
You can create rules in 3 ways.2) Or Using "Create rule from template"
- Create a filter in SEM as per your requirements and send it to Create a new rule.
B) Rule Definition:
1. Select the EventType you want to create a rule against and drag it to the "Rule definition" on the right. 2. Set correlation parameters like rule occurrence "X" times in "Y" duration window. Save and click next.
C) Add Email active response action(s) to the rue under "Details and Actions":
- Under "Details and Actions, click "Add new actions". Search for "Disable Local User Account" and select it and click next.
- On the next step, use the available attributes for the event based on the EventType selected in the rule definition. You can drop down to see the available options. For agent "DestinationMachine" and "DestinationAccount" for the account you plan to monitor and send the user disable action to.
D) How to Validate if Rule is working correctly or not:
- In SEM web console we can validate if the rule has triggered or not under Live Filters tab ➤"Rules Activity" and "SEM Internal Events" Filter(s).
2. Under SEM Internal Events Filter, you should see following sequence of InternalEvents to confirm that Rule is fired and Disable Local User Account Action is also completed.