Hi Prasannanayagi, Customer think his DC server was attacked by ransom virus. which product can help him ? ela ? Prasannanayagi Yes. EventLog Analyzer can help him. If he has setup File Integrity Monitoring, they can check the file created flow ...
1. Wbemtest 测试 If you see the status of RPC Server unavailable and, access denied, then the logs won't be collected. if that is the case, you cannot see the logs in the Search tab or home tab. Kindly run the WBEM TEST. EventLog Analyzer uses WMI API ...