The computer attempted to validate the credentials for an account
How to Audit Organizational Units (OUs) Changes in Active Directory
Centralized logging using Graylog
winlogbeat_event_id:4624 AND winlogbeat_event_data_LogonType:2
winlogbeat_event_id:4624 AND winlogbeat_event_data_LogonType:3
winlogbeat_event_id:4624 AND winlogbeat_event_data_LogonType:10
winlogbeat_event_id:4624 AND winlogbeat_event_data_LogonType:11
winlogbeat_event_id:4625 AND winlogbeat_event_data_LogonType:2 winlogbeat_event_id:4625 AND winlogbeat_event_data_LogonType:3 winlogbeat_event_id:4625 AND winlogbeat_event_data_LogonType:10 winlogbeat_event_id:4625 AND winlogbeat_event_data_LogonType:11
winlogbeat_event_id:4648
winlogbeat_event_id:4675
winlogbeat_event_id:4776 AND NOT winlogbeat_event_data_Status:0x0
winlogbeat_event_id:4634 AND winlogbeat_event_data_LogonType:2 winlogbeat_event_id:4634 AND winlogbeat_event_data_LogonType:3 winlogbeat_event_id:4634 AND winlogbeat_event_data_LogonType:10 winlogbeat_event_id:4634 AND winlogbeat_event_data_LogonType:11
winlogbeat_event_id:4647
winlogbeat_event_id:4720
winlogbeat_event_id:4722
winlogbeat_event_id:(4723 OR 4724)
winlogbeat_event_id:4725
winlogbeat_event_id:4726
winlogbeat_event_id:4738
winlogbeat_event_id:4740
winlogbeat_event_id:4767
winlogbeat_event_id:4780
winlogbeat_event_id:4781
winlogbeat_event_id:4794
winlogbeat_event_id:5376
winlogbeat_event_id:5377
winlogbeat_event_id:4741
winlogbeat_event_id:4742
winlogbeat_event_id:4743
winlogbeat_event_id:(4727 AND 4731 AND 4754)
winlogbeat_event_id:(4728 AND 4732 AND 4756)
winlogbeat_event_id:(4729 AND 4733 AND 4757)
winlogbeat_event_id:(4730 AND 4734 AND 4758)
winlogbeat_event_id:5137
winlogbeat_event_id:5136
winlogbeat_event_id:5139
winlogbeat_event_id:5141
# Needed for Graylog
fields_under_root: true
fields.collector_node_id: ${sidecar.nodeName}
fields.gl2_source_collector: ${sidecar.nodeId}
output.logstash:
hosts: ["${user.host}:${user.port}"]
path:
data: C:\Program Files\Graylog\sidecar\cache\winlogbeat\data
logs: C:\Program Files\Graylog\sidecar\logs
tags:
- winadaudit
winlogbeat:
event_logs:
- name: Security
processors:
- drop_event.when.not.or:
- equals.event_id: 4624
- equals.event_id: 4625
- equals.event_id: 4776
- equals.event_id: 5136
- equals.event_id: 5137
- equals.event_id: 5138
- equals.event_id: 5139
- equals.event_id: 5141
- equals.event_id: 4720
- equals.event_id: 4723
- equals.event_id: 4724
- equals.event_id: 4725
- equals.event_id: 4726
- equals.event_id: 4767
- equals.event_id: 4780
- equals.event_id: 4781
- equals.event_id: 4741
- equals.event_id: 4742
- equals.event_id: 4743
- equals.event_id: 4727
- equals.event_id: 4728
- equals.event_id: 4729
- equals.event_id: 4730
- equals.event_id: 4730
- equals.event_id: 4731
- equals.event_id: 4732
- equals.event_id: 4733
- equals.event_id: 4754
- equals.event_id: 4756
- equals.event_id: 4757
- equals.event_id: 4758
ignore_older: 48h