1。windows server2008R27
server2008ID4624ID
winlogon.exe
2。
XML
* [EventData[数据[@ name=' ProcessName ']和(数据=c: \ windows \ system32系统\ winlogon.exe”)]],
(PrcessNamewinlogon.exe)
3。windows server 2012 windows server2012
* [EventData[数据[@ name=' ProcessName ']和(数据=c: \ windows \ system32系统\ winlogon.exe”)]],
* [EventData[数据[@ name=' LogonType ']和(数据=' https://www.yisu.com/zixun/10 ')]],
XML