Hello All
I try to monitor some special AD groups (Domain Admin) and also others admin groups.
I followed some older blogs from technet and some mvps.
http://blogs.technet.com/b/kevinholman/archive/2009/02/25/authoring-rules-for-windows-2008-events-and-how-to-cheat.aspx
My problem is, when I set the filter for the domain admin groups with "Parameter 3" I didn't recive any events/alerts in scom. But when I set the rule only for the event id 4728 it works without "Parameter 3" and Event Source Security, I will recive all changes from any global group in the domain.
Thanks for help