- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Searching events after log
JacobWrdz
Explorer
10-21-2020
06:13 AM
Hello,
I would like to create the alert that:
someone login to system (event login = successful login) and I just want to check if in 5 min from this event, was any user or group was created by user (which is not member of admin group).
or another version:
If X notification was triggered + notification about new user or new group was triggered (created not by admin)- but 1h before and 1h after notification X (timestamp), then: generate alert
Could you please provide some tips for this case?
Best regards,
Jacob
