Is there a Quest InTrust document or utility which would allow me to look up real-time monitoring rules that include specific Windows Server Security Event ID?
Included with the download package for InTrust is a document called "WindowsAuditingReferences.xls". Upon viewing this document there is tab at the bottom for real-time monitoring. Here you can set column filters for the specific events you are interested in and only the applicable rules will be displayed.
© ALL RIGHTS RESERVED. Nutzungsbedingungen Datenschutz Cookie Preference Center