ldap-binding-change-custom-view.xml 3.1 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546
  1. <ViewerConfig>
  2. <QueryConfig>
  3. <QueryParams>
  4. <Simple>
  5. <Channel>Directory Service</Channel>
  6. <EventId>2886,2887,2888,2889</EventId>
  7. <RelativeTimeInfo>0</RelativeTimeInfo>
  8. <BySource>False</BySource>
  9. </Simple>
  10. </QueryParams>
  11. <QueryNode>
  12. <Name LanguageNeutralValue="LDAP Signing Events">LDAP Signing Events</Name>
  13. <Description>All events related to LDAP signing on Domain Controllers</Description>
  14. <QueryList>
  15. <Query Id="0" Path="Directory Service">
  16. <Select Path="Directory Service">*[System[(EventID=2886 or EventID=2887 or EventID=2888 or EventID=2889)]]</Select>
  17. </Query>
  18. </QueryList>
  19. </QueryNode>
  20. </QueryConfig>
  21. <ResultsConfig>
  22. <Columns>
  23. <Column Name="Level" Type="System.String" Path="Event/System/Level" Visible="">190</Column>
  24. <Column Name="Keywords" Type="System.String" Path="Event/System/Keywords">70</Column>
  25. <Column Name="Date and Time" Type="System.DateTime" Path="Event/System/TimeCreated/@SystemTime" Visible="">240</Column>
  26. <Column Name="Source" Type="System.String" Path="Event/System/Provider/@Name" Visible="">235</Column>
  27. <Column Name="Event ID" Type="System.UInt32" Path="Event/System/EventID" Visible="">150</Column>
  28. <Column Name="Task Category" Type="System.String" Path="Event/System/Task" Visible="">151</Column>
  29. <Column Name="User" Type="System.String" Path="Event/System/Security/@UserID">50</Column>
  30. <Column Name="Operational Code" Type="System.String" Path="Event/System/Opcode">110</Column>
  31. <Column Name="Log" Type="System.String" Path="Event/System/Channel">80</Column>
  32. <Column Name="Computer" Type="System.String" Path="Event/System/Computer">170</Column>
  33. <Column Name="Process ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessID">70</Column>
  34. <Column Name="Thread ID" Type="System.UInt32" Path="Event/System/Execution/@ThreadID">70</Column>
  35. <Column Name="Processor ID" Type="System.UInt32" Path="Event/System/Execution/@ProcessorID">90</Column>
  36. <Column Name="Session ID" Type="System.UInt32" Path="Event/System/Execution/@SessionID">70</Column>
  37. <Column Name="Kernel Time" Type="System.UInt32" Path="Event/System/Execution/@KernelTime">80</Column>
  38. <Column Name="User Time" Type="System.UInt32" Path="Event/System/Execution/@UserTime">70</Column>
  39. <Column Name="Processor Time" Type="System.UInt32" Path="Event/System/Execution/@ProcessorTime">100</Column>
  40. <Column Name="Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@ActivityID">85</Column>
  41. <Column Name="Relative Correlation Id" Type="System.Guid" Path="Event/System/Correlation/@RelatedActivityID">140</Column>
  42. <Column Name="Event Source Name" Type="System.String" Path="Event/System/Provider/@EventSourceName">140</Column>
  43. </Columns>
  44. </ResultsConfig>
  45. </ViewerConfig>