My Oracle Support Banner

OCI Logging Analytics - Filtering Of Windows Security Logs (Doc ID 2907719.1)

Last updated on DECEMBER 21, 2022

Applies to:

OCI Logging Analytics Service - Version N/A and later
Information in this document applies to any platform.

Goal

Receiving huge amount of Windows security logs for Event ID 4663, 4660 & 4688.

 

  1. How to fine tune it
  2. Is is possible to drop the events for particular event IDs and field values(say Account containing $) at the Log Source level.


 

 

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Goal
Solution


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.