We use cookies to try and give you a better experience in Freshdesk.
You can learn more about what kind of cookies we use, why, and how from our Privacy policy. If you hate cookies, or are just on a diet, you can disable them altogether too. Just note that the Freshdesk service is pretty big on some cookies (we love the choco-chip ones), and some portions of Freshdesk may not work properly if you disable cookies.
We’ll also assume you agree to the way we use cookies and are ok with it as described in our Privacy policy, unless you choose to disable them altogether through your browser.
I would like to determine baseline max. changes for configuring EventSentry against ransomware with Windows Auditing and Event ID 4663.
0 Votes
Ingmar Koecher posted almost 7 years ago Admin Best Answer
You can do this by (temporarily) creating a file access tracking package which will normalize all 4663 events recorded by a monitored host.
Simply click on "Compliance Tracking" under "Packages" and create a new package. Assign the package accordingly.
Then, add the "File Access" object to it. Configure that object for "Track all file access activity" and click the "Configure" button to customize it (this is to filter out unwanted data).
Then simply push the configuration to the target hosts and wait until some file access activity has been generated. You can then view file access tracking data in the web reports under "Compliance -> File Access", similar to here: http://demo.eventsentry.com/fileaccess?PROFILE=English.
The summary page already shows you the data grouped by various properties, such as the user name, but you can click the blue header columns as well to get more detailed reporting.
0 Votes
1 Comments
Ingmar Koecher posted almost 7 years ago Admin Answer
You can do this by (temporarily) creating a file access tracking package which will normalize all 4663 events recorded by a monitored host.
Simply click on "Compliance Tracking" under "Packages" and create a new package. Assign the package accordingly.
Then, add the "File Access" object to it. Configure that object for "Track all file access activity" and click the "Configure" button to customize it (this is to filter out unwanted data).
Then simply push the configuration to the target hosts and wait until some file access activity has been generated. You can then view file access tracking data in the web reports under "Compliance -> File Access", similar to here: http://demo.eventsentry.com/fileaccess?PROFILE=English.
The summary page already shows you the data grouped by various properties, such as the user name, but you can click the blue header columns as well to get more detailed reporting.
0 Votes
Login or Sign up to post a comment