Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Non Domain Controller Active Directory Replication (Windows Security Events/Analytic Rules/NonDCActiveDirectoryReplication) #11544

Open
jlextremeiro opened this issue Dec 10, 2024 · 2 comments
Assignees

Comments

@jlextremeiro
Copy link

In the Solutions/Windows Security Events/Analytic Rules/NonDCActiveDirectoryReplication.yaml
the condition
//| where Computer in (DCServersList)
Shouldn't be
//| where Computer !in (DCServersList).

@v-visodadasi
Copy link
Contributor

Hi @jlextremeiro , Thanks for flagging this issue, we will investigate this issue and get back to you with some updates. Thanks!

@v-visodadasi
Copy link
Contributor

v-visodadasi commented Dec 11, 2024

Hi @jlextremeiro , Can you please provide more details and In commented query it already defined as //| where Computer in (DCServersList). So, Could you please provide clarification on this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants