 |
Forums |
Admin Discussion Forums: help Start New Thread
By: Stuart Clarke
Adv evt log descriptions - not retrieved [ reply ] 2009-02-09 19:42
|
Hi,
I have written a regular expression to pull out the IP address of all successful or failed logon attempts of type 10 (this is an RDP logon attempt). When an RDP logon occurs it writes a longer event descriptin like this:
Successful Logon:
User Name: Administrator
Domain: XXXXXXXX
Logon ID: (XXXXXX)
Logon Type: 10
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: XXXXXXX
Logon GUID: -
Caller User Name: XXXXXXXX$
Caller Domain: WORKGROUP
Caller Logon ID: (XXXXXXX)
Caller Process ID: XXXX
Transited Services: -
Source Network Address: XXX.XXX.XXX.XXX
Source Port: XXXX
The source Netwotk Address is the IP address and is not picked up by event description? Is this due to it not being programmed in?
Many thanks
|
|
 |