Date: year, month and day
This represents the date to start the search from. It defaults to the most recent timestamp received from the agent. This is a drop-down automatically configured based on oldest and newest timestamps from the agents.
Time period
The default is 1 month prior. Searches are bounded to predefined periods of 1 day, 1 week, a fortnight, 1 month, 3 months, 6 months, 1 year and all data.
Privilege level
Used to identify logons by privileged accounts. Supports the following predefined options:
Local Admin – The endpoint user belongs to the local administrators group for Windows or the `root`, wheel`, or `sudo` group for Linux.
Domain Admin – User belongs to any of the following privileged domain groups: Enterprise Admins, Schema Admins, Administrators, Domain Admins, Server Operators, Account Operators, and DS Restore Mode Administrator.
Note
This option is provided as a convenience function. It allows quick identification of accounts belonging to known privileged groups.
Privileged – On Windows, when a privileged account logs into a system, it is explicitly annotated in the Windows Security Event log as “privileged” through the generation of a Windows Event 4672. Logon Tracker identifies these logons and annotates them accordingly. This option is very powerful as it enables you to identify any logon event that was considered privileged by the operating system.
ANY – Returns all results, regardless of privilege level no filter is applied.