Remote Interactive Logons
- Remote Interactive Logons
Configuration
query
LogonType:10 AND LogonType:10 NOT EventID:4634 NOT gl2_remote_ip:50.79.122.41
config
Key | Value — | — type | aggregation-v1 query | LogonType:10 AND LogonType:10 NOT EventID:4634 NOT gl2_remote_ip:50.79.122.41 streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000
SIEM Windows Event Log Alerts
.
Last modified
December 31, 1969