- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Domain Controller User or Group Modification
Hello All:
We want to modify the Domain Controller User or Group Modification rule to give it a more narrow focus on Privileged groups only. Has anyone done this already and could share what you did?
Regards,
David
- Labels:
-
FortiSIEM
- « Previous
-
- 1
- 2
- Next »
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, I tested this in the lab on 7.1.x and an incident is generated. Silly question maybe, but the rule is enabled after you imported it, right?
Have you got one of the raw logs that you believe it should trigger on? I could replay them and check the rule in the lab.
Created on
‎03-19-2024
09:55 AM
Edited on
‎03-19-2024
10:15 AM
By
FSM_FTNT
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Our version is 6.7.9.1763.
Here is the raw event:
<admin deleted event>

- « Previous
-
- 1
- 2
- Next »