Removed DC IP to work on any env

keyword-vs-text-changes
Roberto Rodriguez 2017-08-26 11:01:47 -04:00
parent d6980ad919
commit 439c015f57
2 changed files with 2 additions and 4 deletions

View File

@ -97,6 +97,7 @@
"cell_type": "code",
"execution_count": 4,
"metadata": {
"collapsed": true,
"scrolled": false
},
"outputs": [],
@ -113,7 +114,6 @@
" ],\n",
" 'must_not': [\n",
" {\"match\" : {'event_data.IpAddress': \"::1\" }},\n",
" {\"match\" : {'event_data.IpAddress': \"172.18.39.2\" }},\n",
" {\"match\": {'event_data.TargetUserName': \"ANONYMOUS LOGON\"}}\n",
" ],\n",
" \"filter\": [\n",
@ -149,7 +149,6 @@
" {\"match\": {'event_id': 3}}\n",
" ],\n",
" 'must_not': [\n",
" {\"match\" : {'event_data.DestinationIp': \"172.18.39.2\" }}, \n",
" {\"match\" : {'event_data.User': \"NT AUTHORITY\\SYSTEM\"}}\n",
" ],\n",
" \"filter\": [\n",

View File

@ -97,6 +97,7 @@
"cell_type": "code",
"execution_count": 4,
"metadata": {
"collapsed": true,
"scrolled": false
},
"outputs": [],
@ -113,7 +114,6 @@
" ],\n",
" 'must_not': [\n",
" {\"match\" : {'event_data.IpAddress': \"::1\" }},\n",
" {\"match\" : {'event_data.IpAddress': \"172.18.39.2\" }},\n",
" {\"match\": {'event_data.TargetUserName': \"ANONYMOUS LOGON\"}}\n",
" ],\n",
" \"filter\": [\n",
@ -149,7 +149,6 @@
" {\"match\": {'event_id': 3}}\n",
" ],\n",
" 'must_not': [\n",
" {\"match\" : {'event_data.DestinationIp': \"172.18.39.2\" }}, \n",
" {\"match\" : {'event_data.User': \"NT AUTHORITY\\SYSTEM\"}}\n",
" ],\n",
" \"filter\": [\n",