Group of MSDTC events.
Description
Group of MSDTC events.
Query · wazuh
field win.system.providerName="^Microsoft-Windows-MSDTC$"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=windows_eventchannel AND field win.system.providerName="\.+" -
field win.system.channel="^Application$" -
field win.system.severityValue="^INFORMATION$" -
field win.system.providerName="^Microsoft-Windows-MSDTC$"
Refined by
177 rules chain off this one, narrowing it further.
- Unexpected error occurred in the MS DTC XA transaction manager.
- Unable to translate the MS DTC error code to the appropiate MS DTC error message.
- Permission denied to manage the MS DTC on this system.
- Exception occurred while processing control requests from the service control manager.
- The MS DTC has the same unique identity as the local one.
Rule dependencies
Depends on
-
composes · Wazuh if_sid
60600