Forums  Register  Login  My Profile  Inbox  Address Book  My Subscription  My Forums 

Member List  Search  FAQ  Ticket List  Log Out

 

Event ID 560 - Best Way to Handle?

 
Logged in as: Guest
Users viewing this topic: none
  Printable Version
All Forums >> [Networking & Security] >> GFI EventsManager >> Event ID 560 - Best Way to Handle? Page: [1]
Login
Message << Older Topic   Newer Topic >>
Event ID 560 - Best Way to Handle? - 25.Mar.2008 6:16:24 PM   
shoey2u

 

Posts: 3
Score: 0
Joined: 1.Feb.2008
Status: offline
Very Odd....

Since upgrading to EM 8.1, I'm now being flooded with Critical Alerts from my DC's with Event ID 560. I've followed EventID.nets suggestions without any success. I've since created a rule to treat this specific event as noise using criteria from the alert yet I continue receiving the Critical alert via email.

Does anyone have a suggestion or recommendation?

Thanks,

Keith
Post #: 1
RE: Event ID 560 - Best Way to Handle? - 26.Mar.2008 6:20:43 AM   
Sven Berger

 

Posts: 184
Score: 0
Joined: 25.Feb.2008
Status: offline
Hi Shoey2u,

The Event 560 (failed Object Access outside working hours) is considered a "Critical Importance Event" in Eventsmanager. You can either change the Classification of the event (so that you will not get flooded with Emails all the time), or you can create a rule that will treat the event otherwise.

If you would like to have the Event treated as noise, then I would suggest you create a matching rule under "noise Events". You also need to make sure that the rule is applied against evetns that are collected from your machines. I guess that this is where the problem lies.

Go to Configuration -> EventSources and open the properties of the Computer Group where you would like to apply the rule. Open the tab "Windows Event Logs" and tick the radio button "Process the logs with the rules selected before archiving." Expand the "Noise Reduction" node and ensure that your rule has been ticked.

_____________________________

Sven Berger
GFI Software - www.gfi.com
Messaging, Content Security & Network Security Software

(in reply to shoey2u)
Post #: 2
Page:   [1]
All Forums >> [Networking & Security] >> GFI EventsManager >> Event ID 560 - Best Way to Handle? Page: [1]
Jump to:





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts