Notifications from windows

notifications from windows
Hey. I want to receive notifications from my windows log file.
I have a template:
{event.message}</b>{if event.timerange_start}
Timerange: {event.timerange_start} to {event.timerange_end}{end}{if streams}
Streams:{foreach streams stream} <a href='{stream.url}’>{stream.title}</a>{end}{end} {if backlog}{foreach backlog message} ######## Source device: {message.source}
Timestamp: {event.timestamp} test1: {message.full_message}
User: ${message.TargetUserName}

###########
${message.message}
${message.gl2_remote_ip}
${end}</code>${else}<i>- no backlog -</i>
${end}
${if backlog}
${end}

I cannot get the string User: {message.TargetUserName} I can get a complete log. But get message.TargetUserName separately
I can not.

Try ${full_message.TargetUserName}

Here is the message I received:

Windows_block_account
Streams: Windows_block_account 

########
Source device: xdp-dc2
Login: 
###########

User account blocked�

My template:

${event.message}${if event.timerange_start}
Timerange: ${event.timerange_start} to ${event.timerange_end}${end}${if streams}
Streams:${foreach streams stream} ${stream.title}${end}${end}
${if backlog}${foreach backlog message}
########
Source device: ${message.source}

Login: ${full_message.TargetUserName}

###########
${message.message}
${message.gl2_remote_ip}
${end}
${else}- no backlog -
${end}
${if backlog}
${end}

Tried this without results too.
I am using backlog, for Windows it contains all needed fields, including username. Just check message backlog and set it to 1 in event definition and add this to email template

${if backlog}
--- [Backlog] ------------------------------------
Last messages accounting for this alert:
${foreach backlog message}
${message}
${end}

Thank you for helping me.
I also use the backlog for my email.
But I also have notifications set up for my telegram.
These messages are too large for a telegram.
It is not comfortable.

Perhaps you know how to select fields that interest me from the backlog …

No, sorry. Some time ago tried without success, now using full backlog.

I managed to do it.
Maybe someone will come in handy:

<b>${event.message}</b>${if event.timerange_start}
Timerange: ${event.timerange_start} to ${event.timerange_end}${end}${if streams}
Streams:${foreach streams stream} <a href='${stream.url}'>${stream.title}</a>${end}${end}
${if backlog}<code>${foreach backlog message}
${message.message}
${message.gl2_remote_ip}
User: ${message.fields.TargetUserName}
Time: ${message.fields.EventReceivedTime}
Source: ${message.fields.TargetDomainName}
Source device: ${message.source} 

${end}</code>${else}<i>- no backlog -</i>
${end}
${if backlog}
${end}

I receive a message:

Windows_block_account
Streams: Windows_block_account

Заблокирована учетная запись поль�

Source device: xdp-dc1
User: test1
Time: 2020-08-27 17:21:24
Source: XDP-TS1

3 Likes

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.