Hi,
I've been asked to create a rule to monitor when highly privileged accounts logon to our domain. We also need to make sure that we are alerted for all types of logon (Where it be via RDP, Powershell, Fileshare etc)
So i've altered the rule as required and now we are prompted when ever any of the accounts logon. This however generated 3 seperate alerts. One for each logon type used. So in my test environment when I logon as the monitored account I receive 3 alerts for
logon. One for RDP, One for Fileshare and finally another for RDP. - This is just standard for a user logging on.
Further to this we also have a subscription in place to send an email to notify our team when one of the accounts logs on. This is attached to the rule that monitors the accounts.
Becuase of this we are emailed 3 times. - because each alert is different due to the logon type.
Is there any way to roll this up so that it is only 1 alert and further to this the email that is sent out only sends 1 email out but notifies us of all the logon types its used?
So far i've been unsuccessful in getting this to work.
thanks