This article describes how to modify built-in real-time monitoring rule 'Member added to administrative group' so that it will not send alerts if specified users triggered the alert.
After text of the rule is updated new filter 'Authorized Users' will appear in the 'Macthing' tab. Add users who you don't want to trigger the alerts.
The built-in Intrust real-time monitoring rule 'Member added to administrative group' does not have exclusion filters.
Open properties of the rule 'Member added to administrative group', go to 'Matching>Advanced' and replace current text content of the rule with the one provided in the 'Additional Information' field of this article
Additional Information:
<rule type="REL" version="1.0">
<arguments>
<argument displayname="Group List" name="Group List" class="List" description="A list of administrative groups in an organization">
<value>"Administrators", "Domain Admins", "Enterprise Admins", "Schema Admins", "Account Operators", "Backup Operators", "Server Operators"</value>
</argument>
© 2024 Quest Software Inc. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center