Add a field to alert
Posted: Tue Apr 28, 2020 2:43 am
Hi,
I have created a query and an alert for Windows Event ID 4740 (AD account lockout).
The alert runs every 30 minutes and sends an email if there is at least one lockout (in the past 30 minutes).
However, I would like to insert the value of <TargetUserName> to the email so that we know the name of the lockout account.
Currently I don't know how to do that, so every time I receive an alert email, I have to log in to Nagios Log Server, open the query to see the name of the lockout account. It's very inconvenient.
Could you please show me how can I extract that information to the alert email ?
Thank you very much for your help.
I have created a query and an alert for Windows Event ID 4740 (AD account lockout).
The alert runs every 30 minutes and sends an email if there is at least one lockout (in the past 30 minutes).
However, I would like to insert the value of <TargetUserName> to the email so that we know the name of the lockout account.
Currently I don't know how to do that, so every time I receive an alert email, I have to log in to Nagios Log Server, open the query to see the name of the lockout account. It's very inconvenient.
Could you please show me how can I extract that information to the alert email ?
Thank you very much for your help.