cisagov / LME

Logging Made Easy (LME) is a no-cost and open logging and protective monitoring solution serving all organizations.
https://www.cisa.gov/resources-tools/services/logging-made-easy
Other
763 stars 59 forks source link

Upgraded GPOs for Chapter 1 to get more ID Logs #316

Closed rgbrow1949 closed 1 day ago

rgbrow1949 commented 3 weeks ago

Edited the Chapter 1 Group Policy Objects LME-WEC-Client and LME-WEC-Server to now have the audit policies that will yield more ID logs out of active directory on the domain controller.

Closes #235

You can test this by importing the new GPOs and updating the network's group policies. Then perform an action that would trigger one of the new audit policies and find it in the event viewer and see if it is then forwarded to Elastic.

rgbrow1949 commented 1 day ago

Merge conflict issues with this PR. This branch was originally cloned off main but needs to go into 1.4.0. So I need to reclone the branch off 1.4.0. I will need to remake the Pull Request. Will likely and PR and reopen a new one.

rgbrow1949 commented 1 day ago

Closing PR to remake it, cloning off 1.4.0 instead of main