Posted On April 8, 2019

How to Use QRadar to Search for a Windows Account Activities

kimconnect 0 comments
blog.KimConnect.com >> Windows >> How to Use QRadar to Search for a Windows Account Activities

Log into https://qradar/console/qradar/jsp/QRadar.jsp

Log Activity > Add Filter > Parameter=Username[Indexed] | Operator=Equals any of | Value=”UserName” > click on ‘+’ sign > click Add Filter

Click on View > Selection An Option = Last 24 hours

Wait for progress to complete > view through any resulting item

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Post

Microsoft Failover Clustering Service Overview

In Windows 2012 R2, the failover clustering service requires some downtime to migrate clusters from…

Penetration Testing of Active Directory

Foreword: the following information is intended as educational contents and advisories on security topics. Please…

Remote Desktop: Broken Domain Trust Relationship Between Workstation an Primary Domain Controller

Symptom Remote desktop initiation toward a certain server would result in an error message with…