随笔 - 911  文章 - 5  评论 - 94  阅读 - 243万

Zabbix监控事件日志

 

新建服务:eventlog[System,,,"Service control Manager",^7045$,,skip]

新建任务计划:eventlog[Microsoft-Windows-TaskScheduler/Operational,,,"TaskScheduler",^106$,,skip]

删除任务计划:eventlog["Microsoft-Windows-TaskScheduler/Operational",,,"TaskScheduler",^141$,,skip]

修改组策略:eventlog[Security,,,,4739,,]

删除安全日志:eventlog[Security,,,,1102,,]

删除用户:eventlog[Security,,,,4726,,]

用户登录:eventlog[Security,,,,4722,,]

 A member was added to a security-enabled global group:eventlog[Security,,,,4728,,]

trigger:

{Template Windows AD DS Security Audit:eventlog[Security,,,,^4728$].logseverity(0)}>1 and {Template Windows AD DS Security Audit:eventlog[Security,,,,^4728$].nodata(600)}=0 and ({Template Windows AD DS Security Audit:eventlog[Security,,,,^4728$].str(Admins)}=1 or {Template Windows AD DS Security Audit:eventlog[Security,,,,^4728$].str(Management)}=1 or {Template Windows AD DS Security Audit:eventlog[Security,,,,^4728$].str(Group Policy)}=1 or {Template Windows AD DS Security Audit:eventlog[Security,,,,^4728$].str(RODC)}=1 or {Template Windows AD DS Security Audit:eventlog[Security,,,,^4728$].str(Controllers)}=1 )
View Code

A member was added to a security-enabled universal group:eventlog[Security,,,,4756,,]

A memeber was added a security-enabled local group:eventlog[Security,,,,4732,,]

A security-enabled global group was deleted:eventlog[Security,,,,^4730$]

A security-enabled universal group was deleted:eventlog[Security,,,,^4758$]

 

posted on   momingliu11  阅读(380)  评论(0编辑  收藏  举报
编辑推荐:
· AI与.NET技术实操系列(二):开始使用ML.NET
· 记一次.NET内存居高不下排查解决与启示
· 探究高空视频全景AR技术的实现原理
· 理解Rust引用及其生命周期标识(上)
· 浏览器原生「磁吸」效果!Anchor Positioning 锚点定位神器解析
阅读排行:
· DeepSeek 开源周回顾「GitHub 热点速览」
· 物流快递公司核心技术能力-地址解析分单基础技术分享
· .NET 10首个预览版发布:重大改进与新特性概览!
· AI与.NET技术实操系列(二):开始使用ML.NET
· 单线程的Redis速度为什么快?
历史上的今天:
2014-12-23 远程桌面更改域账户密码
2013-12-23 添加虚拟机网卡
< 2025年3月 >
23 24 25 26 27 28 1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31 1 2 3 4 5

点击右上角即可分享
微信分享提示