SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

User and Group Filters

Several templates and reports include User and Group filters. These filters search Active Directory and/or local accounts for:

  • Valid accounts (e.g. Is the account listed in the Event Log entry a valid Active Directory account?)
  • Group assignment (e.g. Does the user belong to the Domain Admins group?)

When a log entry is being filtered, the following Log Entry Column Definition values are filtered:

  • ACCOUNT_NAME
  • TARGET_ACCOUNT_NAME

How to filter users from the User and Group Filters controls:

  • Use the Limit results to valid Active Directory accounts check box to enable group lookup and user validation. Only users that reside in Active Directory pass the filter.
Important
When filtering with an Active Directory Security Group, this option must be selected so the report can download the list of users assigned to each security group.
  • Use the Limit to the following groups and users drop-down to assign specific users and security groups to pass through the filter.
Note
Type any account name or group name, otherwise, use the drop-down to select from the current domain's list of users and groups.
  • Use the Filter out the following groups and users drop-down to filter out specific users and security groups from the results.
Note
Type any account name or group name, otherwise, use the drop-down to select from the current domain's list of users and groups.
Active Directory User and Group Filter Properties View
Active Directory User and Group Filter Properties View

Related Topics

Templates

Reports

Security Event Log Report Filters