Previous Topic: Customize Keyed Values for Critical_Processes

Next Topic: Customize Keyed Values for ELM_System_Lognames

Customize Keyed Values for Default_Accounts

You can use a predefined query to create an alert when a login by a default account is successful. You can use the default keyed list only or you can supplement it with your own values. Predefined values include bin, cisco, daemon, DBSNMP, Guest, helpdesk, Imnadm, invscout, IUSR_ComputerName, mail, Nobody, root, sa, sshd, sys, SYSMAN, system, and Uucp.

To customize the list, you identify the default accounts that are created during operating system, database, or application installations as values in the key-value list for Default_Accounts. The query that uses the values you supply is named Successful Login by Default Accounts in the last 24 hours.

If you create a custom query that uses this key, define the filter as follows:

Column

Operator

Value

dest_username

Keyed

Default_Accounts

To customize keyed values for Default_Accounts

  1. Click the Administration tab and the Services subtab.
  2. Click Report Server.

    A list of keys to which you add user-defined values is displayed at the bottom of the main pane.

  3. Select the key, Default_Accounts.

    The predefined values appear.

  4. Take one or more of the following actions to update this list:
  5. Click Save.

    If you have already scheduled an action alert for the query Successful Login by Default Accounts in the last 24 hours, that alert will be generated based on the evaluation of all values in your modified keyed list for Default_Accounts.

More information:

Example: Send an Alert that Runs an IT PAM Process Per Row