
A LEM Agent on a Windows computer generates several alerts during normal operations that we consider "noise alerts." Basically, these alerts represent background Windows functions, and they are not necessary for an optimized LEM deployment.
The alerts described in the tables below can be disabled using your LEM Manager's Alert Distribution Policy by unchecking their boxes in the Console, Database, Warehouse, and Rules columns.
To modify your LEM Manager's Alert Distribution Policy:
Use this table to manually navigate the alert taxonomy and locate each Windows noise alert.
| Alert Name | Category |
|---|---|
| Machine Logon | Generic Alert > Audit Alert > Auth Audit > Machine Auth Audit |
| Machine Logoff | Generic Alert > Audit Alert > Auth Audit > Machine Auth Audit |
| Machine Auth Ticket | Generic Alert > Audit Alert > Auth Audit > Machine Auth Audit |
| User Auth Ticket | Generic Alert > Audit Alert > Auth Audit > User Auth Audit |
| Policy Scope Change | Generic Alert > Audit Alert > Resource Audit > Policy Audit > Policy Access |
| Alert Name | Description |
|---|---|
| Machine Logon | This alert represents "background" machine authentications and is not related to any interactive user logon activity. |
| Machine Logoff | This alert represents "background" machine authentications and is not related to any interactive user logon activity. |
| Machine Auth Ticket | This alert is related to normal Kerberos ticketing, but it doesn't provide any useful information. It only indicates that a ticket was granted, and doesn't provide any additional detail. |
| User Auth Ticket | This alert is related to normal Kerberos ticketing, but it doesn't provide any useful information. It only indicates that a ticket was granted, and doesn't provide any additional detail. |
| Policy Scope Change | This alert represents Windows servers changing the scope of users' permissions as they access network resources. It occurs every time a user accesses a resource, but doesn't provide any useful data. |
Last Updated
26th of October, 2011