On Wed, Feb 1, 2012 at 4:21 PM, Peter M Abraham
peter.abra...@dynamicnet.net wrote:
Good day:
Given the following rule
rule id=18 level=11
if_sid18107/if_sid
matchLogon Type: 10/match
descriptionWindows RDP Login./description
groupauthentication_success,/group
/rule
What could we add so that if the User Name is not a specific value
AND the Source Network Address is not a specific value, that an
email is triggered to a specific email address?
Thank you.
rule id=180001 level=0
if_sid18/if_sid
userUser Name/user
srcipSource Network Address/srcip
descriptionIgnore stuff/description
/rule
Then create a granular email alert for rule 18.