Skip to main content

SIEM Folder Templates

The SIEM folder contains the following templates:

TemplateDescriptionTAGS
Domain Admin ActivityMonitors for all activity performed by objects that have Domain Admin privileges. Utilizes the built-in “Domain Administrators” – Perpetrator Collection. Add accounts with domain administrator rights to be monitored to this collectionNone
Enabled and Disabled AccountsMonitors when accounts are enabled or disabled. No customizations requiredNone
Failed AuthenticationsMonitors for all Failed Authentications. No customizations requiredNone
GPO Setting ChangesMonitors all GPO setting changes. No customizations requiredNone
OU Moved or RenamedMonitors for all OU moves or renames. No customizations requiredNone
Password ChangesMonitors for password changes. No customizations requiredNone
Sensitive Group ModificationsGathers Successful AD Authentications. Utilizes built-In “Successful Authentications” – Include Perpetrators Collection to define which accounts will be monitored for successful authentications. Add desired accounts to be monitored to this collectionNone
Successful LogonsTo minimize database growth, this policy is not set to send events to the reporting database, IT ONLY SENDS its information to SIEM. Make sure the Configuration > Event Filtering > Exclude 'Noise' Events option is Off for this policy. No customizations required.None
SYSVOL TamperingMonitors for changes to critical files under SYSVOL. Specify the SYSVOL folders for all the servers to be monitored.None
User LockoutsMonitors for user lockouts. No customizations required.None