Team, I am trying to setup a use case about
To detect if Local admin account has been used to logon to a system , would appreciate response over it...
This should return what you're looking for:
index=_audit user=admin action="login attempt"
Hi, Thanks for responding.
However, the existing computer is connected to domain and i am trying to monitor if Someone trying to logon to the local computer and bypassing domain.
In the above query - i am not able to find any such action type.