Query not matching Alerts
Posted: Wed Nov 06, 2019 9:46 am
Hi:
I have a query that is working fine as a dashboard but when I set it as an alert it isn't accurate. Here is the query:
EventID: 7045 and ((ServiceName: "WCESERVICE" or ServiceName: "WCE SERVICE") or (ImagePath: "PSExec") or (ImagePath: "winexesvc.exe") or (ImagePath: "DumpSvc.exe") or (ServiceName: "mssecsvc2.0") or (ImagePath: " *net user * ") or (ServiceName: "pwdump" or ServiceName: "gsecdump" or ServiceName: "cachedump"))
It tests fine in the dashboard and has no hits. When I set the alert it returns almost 60000 results in a 5 minute check window.
Thanks!
I have a query that is working fine as a dashboard but when I set it as an alert it isn't accurate. Here is the query:
EventID: 7045 and ((ServiceName: "WCESERVICE" or ServiceName: "WCE SERVICE") or (ImagePath: "PSExec") or (ImagePath: "winexesvc.exe") or (ImagePath: "DumpSvc.exe") or (ServiceName: "mssecsvc2.0") or (ImagePath: " *net user * ") or (ServiceName: "pwdump" or ServiceName: "gsecdump" or ServiceName: "cachedump"))
It tests fine in the dashboard and has no hits. When I set the alert it returns almost 60000 results in a 5 minute check window.
Thanks!