s0p4L1n3 / Graylog_Content_Pack_Windows_Security

MIT License
6 stars 1 forks source link

Issue with setting up Graylog Content Pack #2

Open Ramonescat opened 1 week ago

Ramonescat commented 1 week ago

Hello, I would like to know which step I did wrong that caused Dashboards to not see the data flow. I have made the changes to Windows-Security-Content-Pack.json as you mentioned, but I’m unsure where the error might be. If my server name is DC, should I modify it to just DC or should I modify it to (nameDC OR name2 OR name3)? 螢幕擷取畫面 2024-06-26 093006

s0p4L1n3 commented 1 week ago

If you have only one domain controller, replace NOT source: (DC OR name2 OR name3) with NOT source: DC The OR condition is only when you have multiple domain controller on your infrastructure.