The easiest way to get notified in realtime whenever a user is created in Active Directory is by forwarding MicrosoftWindowsSecurityAuditing event 4720https://system32.eventsentry.com/security/event/4720. This event is logged to the Security event log whenever an Active Directory user is created. More informa...

KB-ID 403
Category: Security

The easiest way to get notified in realtime whenever specific service/driver starts or stops is by forwarding EventSentry event 10100 or 10150. This particular event is logged by EventSentry when a service or drivers status changes. Service monitor is a feature that is enabled by default in EventSentry under System Health Services...

KB-ID 405
Category: Service Monitoring

The easiest way to get notified in realtime whenever a user attempts to log on more than X times with a wrong password is by forwarding MicrosoftWindowsSecurityAuditing event 4625https://system32.eventsentry.com/security/event/4625. This event is logged to the Security event log whenever a user fails to logon. More...

KB-ID 407
Category: Compliance

EventSentry can be configured to restart services based on their resource usage. For example when a service uses more than the specified amount of memory handles or CPU a service restart can be triggered. Steps: 1. Creating a Performance Monitoring Package 2. Configuring the Performance Monitoring Package 3. Creating and Configuring ...

KB-ID 448
Category: Monitoring
Applies to: 4.1 and later

This guide explains how to deploy the HWgSTE Ethernet temperature / humidity sensor in your server room or office. Note: Please see the links below if you have not yet purchased the HWgSTE. Steps: 1. Unboxing and connecting the sensors 2. Connecting to the HWgSTE and configuring it 3. Adding the sensor to EventSentry Un...

KB-ID 453
Category: Monitoring
Applies to: 3.1 and later

Windows generates an event ID 4688https://system32.eventsentry.com/security/event/4688 in the Windows Security Event Log when a process gets launched. In EventSentry an include filter to monitor for those events needs to be created and associated with an email action so that an email alert is sent once this specific process gets started....

KB-ID 457
Category: Event Log Monitoring
Applies to: all