When
|
At what date and time a user activity originated in the system.
|
DateTime
|
10.10.2000 19:00:00
|
Who
|
Account or user name under which the activity occured.
|
Subject: Account Name
|
Administrator
|
What
|
The type of activity occurred (e.g. Logon, Password Changed, etc.)
|
"Process Terminated"
|
Process Terminated
|
Where
|
The name of the workstation/server where the activity was logged.
|
Computer
|
DC1
|
Where From
|
The name of the workstation/server where the activity was initiated from.
|
-
|
10.10.10.10
|
Severity
|
Specify the seriousness of the event.
|
"Medium"
|
Medium
|
WhoDomain
|
|
Subject: Account Domain
|
LOGISTICS
|
WhereDomain
|
|
-
|
|
Program Name
|
The name of the executed program/process.
|
Process Information: Process Name
|
C:\Generate_Security_Events1\auditon.exe
|