Submit a ticketCall us

Looking to compare latest NPM features with previous versions of NPM?
The NPM new feature summary offers a comparison of new features and improvements offered with this release.

 

Home > Success Center > Log & Event Manager (LEM) > Enabled account rule is also firing for create user events

Enabled account rule is also firing for create user events

Created by Jason Dee, last modified by MindTouch on Jun 23, 2016

Views: 4 Votes: 1 Revisions: 4

Overview

This article provides brief information and steps to resolve the issue when the rule created to alert you for account enabled events is not firing for create user events.

 

Environment

All LEM versions

 

Cause 

The issue is caused when a user account is created in the Active Directory. Windows will immediately follow the create user event with an account enabled event which causes a false positive.

 

Resolution

Modify your rule correlations to ignore the account enabled events if it accompanies a create user event. Modify your rule to match screenshot.  Save your changes, and click Activate Rules.

 

 

 

 

 

Last modified
19:59, 22 Jun 2016

Tags

Classifications

Public