Solved

Filtering event 4624 by logon type

Posted on 2012-04-12
3
4,220 Views
Last Modified: 2012-04-12
I'm looking to find a way to filter event 4624 by logon type.  I want to only get logon type 2 and logon type 10.  Since the logon type is written in the message of the event I can't think of a way to filter on it.  The only way I've found is to dump all the 4624's to a text file via script and just search for type 2 and 10.  But I'd like to automate this if possible.
0
Comment
Question by:bigbigpig
  • 2
3 Comments
 
LVL 17

Accepted Solution

by:
Anuroopsundd earned 500 total points
ID: 37840869
In event viewer

under custom views.
Right click new view
Create Custom view

specify the even id and other details... this wll create the xml automatically
then under XML tab.. select check box edit query manually.. and change as per your requirement... below is just an example...you may have to modify for type of event (System,Security, Application.) if the line is comming multiple times...


<Select Path="S">*[System[(Level=2 or Level=10) and (EventID=4624)]]
0
 
LVL 10

Author Comment

by:bigbigpig
ID: 37841019
That didn't work but you got me in the right direction!  I looked in the events metadata to figure out what to query.  Here's what I used:

<Select Path="Security">*[System[(EventID=4624)]] and *[EventData[Data[@Name='LogonType'] and (Data=2 or Data=10)]]</Select>

Open in new window


Thank you!
0
 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37841024
yeah.. i should have mentioned that those where just the steps how to do..
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help you understand what HashTables are and how to use them in PowerShell.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now