Skip to content

Instantly share code, notes, and snippets.

@MarkUlmer
Created August 28, 2017 16:17
Show Gist options
  • Save MarkUlmer/14ec5290ea24ba6e5b02dcf65946323c to your computer and use it in GitHub Desktop.
Save MarkUlmer/14ec5290ea24ba6e5b02dcf65946323c to your computer and use it in GitHub Desktop.
ArcSight Logger Search - Windows Events for Group Changes
deviceEventClassId IN ["Microsoft-Windows-Security-Auditing:4758","Microsoft-Windows-Security-Auditing:4754","Microsoft-Windows-Security-Auditing:755","Microsoft-Windows-Security-Auditing:4735","Microsoft-Windows-Security-Auditing:4734","Microsoft-Windows-Security-Auditing:4731","Microsoft-Windows-Security-Auditing:4730","Microsoft-Windows-Security-Auditing:4727","Microsoft-Windows-Security-Auditing:4737"] and NOT (destinationUserName ENDSWITH "$") and NOT (sourceUserName ENDSWITH "$")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment