Submit a ticketCall us

Welcome to the NEW Success Center. Search all resources (documentation, videos, training, knowledge base articles) or browse resources by product. If you are unable to find what you are looking for, please contact us at customersuccess@solarwinds.com

 

 

 

 

Home > Success Center > Log & Event Manager (LEM) > Enabled account rule is also firing for create user events

Enabled account rule is also firing for create user events

Created by Jason Dee, last modified by MindTouch on Jun 23, 2016

Views: 634 Votes: 1 Revisions: 4

Overview

This article provides brief information and steps to resolve the issue when the rule created to alert you for account enabled events is not firing for create user events.

 

Environment

All LEM versions

 

Cause 

The issue is caused when a user account is created in the Active Directory. Windows will immediately follow the create user event with an account enabled event which causes a false positive.

 

Resolution

Modify your rule correlations to ignore the account enabled events if it accompanies a create user event. Modify your rule to match screenshot.  Save your changes, and click Activate Rules.

 

 

 

 

 

Last modified
19:59, 22 Jun 2016

Tags

Classifications

Public