David J Kelly

Search
Skip to content
  • About David

Monthly Archives: August 2020

Event COLLECTOR for logons (RDP)

August 6, 2020 David Kelly Leave a comment

in order to collect who is logging on to Server via Remote Sessions and event subscription can be created with the following XML filters

*[System[(EventID=4624 or EventID=4625)]] and *[EventData[Data[@Name=’LogonType’] and Data=10]]

More System and Enterprise Architecture…

Tags

  • Certificate Authority
  • Event Viewer
  • Powershell
  • Windows

Recent Posts

  • Event COLLECTOR for logons (RDP)
  • Certificate Authority: Certification issuing in the Enterprise
  • Kerberos tickets of the system account for Computer Group membership
  • Powershell send-mailmessage from task scheduler
  • Powershell Query Services on Remote Computer

Recent Comments

    Archives

    • August 2020
    • November 2017
    • September 2017
    • September 2016
    • August 2016

    Categories

    • Uncategorized

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
    To find out more, including how to control cookies, see here: Cookie Policy
    Proudly powered by WordPress