FG
02/21/2024, 7:45 PMFG
02/21/2024, 7:46 PMSELECT * FROM windows_eventlog WHERE eventid = 4663 AND channel = "Security" and keywords = "Audit Success" AND xpath LIKE "%ScreenConnect%" LIMIT 10;
FG
02/21/2024, 7:46 PMStefano Bonicatti
02/21/2024, 7:55 PM--disable_tables=windows_eventlog
Just to understand, have you tried to query a single machine with this?
I would also check with #C01DXJL16D8FG
02/21/2024, 7:55 PMStefano Bonicatti
02/21/2024, 7:56 PMFG
02/21/2024, 7:56 PM