Topic
  • 1 reply
  • Latest Post - ‏2016-07-28T10:28:27Z by Nikodim
benthere9
benthere9
1 Post

Pinned topic rule for two events in different categories, event properties that match

‏2016-07-26T22:56:47Z |

I want to create an offense rule that alerts when a user is created on a Windows computer and that same user logs in with administrator access.  It's two separate events in two different categories with two different event properties that need to match.

 

First event:  BB:CategoryDefinition: User Account Created with Event Property:  New Account Name (custom)

Second event:  BB:CategoryDefinition: Admin Login Successful with Event Property: Username

 

The two event properties should match.

 

What should the syntax of the rule be?

 

Thanks!

  • Nikodim
    Nikodim
    11 Posts

    Re: rule for two events in different categories, event properties that match

    ‏2016-07-28T10:28:27Z  

    Hi,

    I would suggest following scenario:

    1) Create a new custom property "Affected User" for both event types, with different regexes but the same name, extracting new account name from first event and user name for the second.

    2) Create a rule #1 matching first event and "Affected User" is not N/A

    3) Create a rule #2 matching second event and "Affected User" is not N/A

    4) Create a rule #3 which will expect rule #1 followed by rule #2 with the same property "Affected User"