The category of logon event. Supports the predefined options described below. For more information on Windows Event IDs, see Windows Logon Events and Windows Logon Types sections.
Local: Any local logon
Network:Windows Event ID 4624/4625 of type 3 (Network) or Windows Event ID 4648 (incoming or outgoing) and not accessing a share.
Network Share:
Windows Event ID 5145.
Windows Event ID 4648 and destined for a CIFS (Common Internet File System).
RDP: Windows Event ID 4624 if type 10 (RemoteInteractive) or Windows Event ID 21/25.
SSH: SSH events from Linux systems.
ARD: Apple Remote Desktop from macOS systems
PsExeco: PsExec logon using Sys Internals tool or a similar technique. Enriched from 4624 network event.
WMI: Windows Management Instrumentation logon activity which was enriche from a 4624 network event.
WinRM: Windows Remote Management logon activity which was enriched from a 4624 network event.
RPCo: Windows Remote Procedure Call logon activity which was enriched from a 4624 network event.
LDAP: LDAP logon and query which was enriched from a 4624 network event.
Any – Returns all results, regardless of type, no filter is applied.