In order for the alert to work, both Eventcodes have to be activated.
query | search EventCode=4663 OR EventCode=4776 | table _time,EventCode,Message,
I am making some assumptions:
1.) you expect the events to happen on the same host, and in a specific order (4663 followed by 4776)
2.) you expect the events to occur within a specified period of time (300 seconds)
3.) you don't care about other events which may have occurred in the meantime.
In which case the following should give you a result each time the above occurs:
( EventCode=4663 OR EventCode=4776) | transaction host maxspan=300s startswith="EventCode=4663" endswith="EventCode=4776"|table _time,host,EventCode,Message
I am making some assumptions:
1.) you expect the events to happen on the same host, and in a specific order (4663 followed by 4776)
2.) you expect the events to occur within a specified period of time (300 seconds)
3.) you don't care about other events which may have occurred in the meantime.
In which case the following should give you a result each time the above occurs:
( EventCode=4663 OR EventCode=4776) | transaction host maxspan=300s startswith="EventCode=4663" endswith="EventCode=4776"|table _time,host,EventCode,Message
it does thank you
Generally in windows logs for every event there will be one EventCode per event .
unable to understand the criteria "For triggerring the alert both event codes have to be activated?"
Per my understanding , does the alert needs to trigger if both the event codes occur with time difference ?
no, the suggestion that was provided will suffice, thank you