<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to optimize alerts for changes made to the Administrators group in &amp;quot;MF Local Admin Group Member Changes&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-alerts-for-changes-made-to-the-Administrators/m-p/673890#M112812</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One of our MF Local Administrative Group Member rule is generating a significant number of alerts because sccmadmin group removed from MF member server, assistance is needed in refining this search to minimize unnecessary alerts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=foo sourcetype=XmlWinEventLog (EventCode=4732) dest="mf" user!="nt service"&lt;BR /&gt;NOT (EventCode="4732" src_user="root" MemberSid="Domain Admins" Group_Name="Administrators")&lt;BR /&gt;NOT (EventCode="4732" MemberSid="NT SERVICE\\*" (Group_Name="Administrators" OR Group_Name="Remote Desktop Users"))&lt;BR /&gt;| eval user=lower(MemberSid)&lt;BR /&gt;| eval src_user=lower(src_user)&lt;BR /&gt;| stats values(user) as user, values(Group_Domain) as Group_Domain, values(dest) as dest by src_user,Group_Name,EventCode,signature _time&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks...&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2024 07:19:58 GMT</pubDate>
    <dc:creator>smith_</dc:creator>
    <dc:date>2024-01-11T07:19:58Z</dc:date>
    <item>
      <title>How to optimize alerts for changes made to the Administrators group in "MF Local Admin Group Member Changes"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-alerts-for-changes-made-to-the-Administrators/m-p/673890#M112812</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One of our MF Local Administrative Group Member rule is generating a significant number of alerts because sccmadmin group removed from MF member server, assistance is needed in refining this search to minimize unnecessary alerts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=foo sourcetype=XmlWinEventLog (EventCode=4732) dest="mf" user!="nt service"&lt;BR /&gt;NOT (EventCode="4732" src_user="root" MemberSid="Domain Admins" Group_Name="Administrators")&lt;BR /&gt;NOT (EventCode="4732" MemberSid="NT SERVICE\\*" (Group_Name="Administrators" OR Group_Name="Remote Desktop Users"))&lt;BR /&gt;| eval user=lower(MemberSid)&lt;BR /&gt;| eval src_user=lower(src_user)&lt;BR /&gt;| stats values(user) as user, values(Group_Domain) as Group_Domain, values(dest) as dest by src_user,Group_Name,EventCode,signature _time&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 07:19:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-optimize-alerts-for-changes-made-to-the-Administrators/m-p/673890#M112812</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2024-01-11T07:19:58Z</dc:date>
    </item>
  </channel>
</rss>

