- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How do I configure a forwarder to whitelist only Event Code 4624 and Logon Types 2 or 11?
davidec137
New Member
12-13-2018
09:20 AM
I'm trying to edit inputs.conf in my forwarder to show ONLY Event 4624, with only Logon Type 2 or 11. I've seen many examples online of similar things, but nothing has worked for me so far. I understand I need to parse the Logon Type out of the Message field.
What would I have to add to this:
[WinEventLog://Security]
disabled=0
whitelist1 = EventCode="4624" Message="what's here?"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
davidec137
New Member
12-13-2018
10:57 AM
One of my coworkers may have come up with the answer:
whitelist1 = EventCode=4624 Message="Logon Type:\s+[2, 11]"
