pantagruel
2007-08-21 13:58:00 UTC
Anyone see any reason why this WQL should not return any instances if
there are instances matching the following rules:
The time range to check is today to yesterday at this time.
The event code for the Security NTLogEvent is 528 or 551.
---------------------------
Windows Script Host
---------------------------
Select * from Win32_NTLogEvent Where Logfile = 'Security' And
(EventCode = '528' Or EventCode ='551') And TimeWritten >=
'20070820000000.000000+120' and TimeWritten <
'20070821000000.000000+120'
---------------------------
OK
---------------------------
Cheers,
Bryan Rasmussen
there are instances matching the following rules:
The time range to check is today to yesterday at this time.
The event code for the Security NTLogEvent is 528 or 551.
---------------------------
Windows Script Host
---------------------------
Select * from Win32_NTLogEvent Where Logfile = 'Security' And
(EventCode = '528' Or EventCode ='551') And TimeWritten >=
'20070820000000.000000+120' and TimeWritten <
'20070821000000.000000+120'
---------------------------
OK
---------------------------
Cheers,
Bryan Rasmussen