I’m looking for a way to setup my Notification and/or Alerts for a specific time.
I Created a Stream Called:
Windows: User Successful Logon to Computer
The rules are:
Field EventID must match exactly 4624 (Successful login)
Field LogonType must match exactly 2 (A user logged on to this computer.)
This notifies me when any user/s logged into a Windows machine, from there I configure Event Definitions called:
User Has Logon Outside Business Hours
I’m trying to set it up to receive alerts from the hours of 5PM to 8 AM.
I don’t know if this is possible. I tried to create different field called user_time but it just gave me all the users logged in for the day.
CentOS 7 Latest Version
Also, I looked through here. Maybe I missed something.
Any advice, Ideas or direction would be appreciated.
Thank you in advance.