I am attempting to blacklist all Domain Controller events of a specific class on our domain controllers. While I have the blacklist working, it is doing it for all events for that user class - I want drop all successes while keeping any failures for troubleshooting.
blacklist1 = EventCode="^(4624|4634|4648|4776)$" Message=".+(?i:bob)|.+(?i:joe)"
I have tried the following with no success (pun unintented)
blacklist1 = EventCode="^(4624|4634|4648|4776)$" Message=".+(?i:Audit Success).+(.+(?i:bob)|.+(?i:joe))"
Any suggestions?
... View more