{"id":677,"date":"2015-03-20T17:01:03","date_gmt":"2015-03-20T15:01:03","guid":{"rendered":"http:\/\/dety.net.ua\/?p=677"},"modified":"2015-03-23T15:33:03","modified_gmt":"2015-03-23T13:33:03","slug":"events-scheduler-email-when-someone-is-connected-via-rdp","status":"publish","type":"post","link":"https:\/\/dety.net.ua\/?p=677","title":{"rendered":"Events + Scheduler + Email when someone is connected via RDP"},"content":{"rendered":"<p>Just edit and import XML-file into Task Scheduler.<\/p>\n<p>There is XML:<\/p>\n<blockquote><p>&lt;?xml version=&#8221;1.0&#8243; encoding=&#8221;UTF-16&#8243;?&gt;<br \/>\n&lt;Task version=&#8221;1.2&#8243; xmlns=&#8221;http:\/\/schemas.microsoft.com\/windows\/2004\/02\/mit\/task&#8221;&gt;<br \/>\n&lt;RegistrationInfo&gt;<br \/>\n&lt;Date&gt;2013-07-26T06:55:11.4860707&lt;\/Date&gt;<br \/>\n&lt;Author&gt;Me&lt;\/Author&gt;<br \/>\n&lt;Description&gt;Sends emails when server is accessed via RDP (Flag 10 &#8211; Remote connect).&lt;\/Description&gt;<br \/>\n&lt;\/RegistrationInfo&gt;<br \/>\n&lt;Triggers&gt;<br \/>\n&lt;EventTrigger&gt;<br \/>\n&lt;Enabled&gt;true&lt;\/Enabled&gt;<br \/>\n&lt;Subscription&gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id=&#8221;0&#8243; Path=&#8221;Security&#8221;&amp;gt;&amp;lt;Select Path=&#8221;Security&#8221;&amp;gt;*[System[(EventID=4624)]] and *[EventData[Data[@Name=&#8217;LogonType&#8217;] and (Data=10)]]&amp;lt;\/Select&amp;gt;&amp;lt;\/Query&amp;gt;&amp;lt;\/QueryList&amp;gt;&lt;\/Subscription&gt;<br \/>\n&lt;ValueQueries&gt;<br \/>\n&lt;Value name=&#8221;IpAddress&#8221;&gt;Event\/EventData\/Data[@Name=&#8221;IpAddress&#8221;]&lt;\/Value&gt;<br \/>\n&lt;Value name=&#8221;TargetUserName&#8221;&gt;Event\/EventData\/Data[@Name=&#8221;TargetUserName&#8221;]&lt;\/Value&gt;<br \/>\n&lt;Value name=&#8221;WorkstationName&#8221;&gt;Event\/EventData\/Data[@Name=&#8221;WorkstationName&#8221;]&lt;\/Value&gt;<br \/>\n&lt;Value name=&#8221;eventRecordID&#8221;&gt;Event\/System\/EventRecordID&lt;\/Value&gt;<br \/>\n&lt;\/ValueQueries&gt;<br \/>\n&lt;\/EventTrigger&gt;<br \/>\n&lt;\/Triggers&gt;<br \/>\n&lt;Principals&gt;<br \/>\n&lt;Principal id=&#8221;Author&#8221;&gt;<br \/>\n&lt;UserId&gt;Administrator&lt;\/UserId&gt;<br \/>\n&lt;LogonType&gt;Password&lt;\/LogonType&gt;<br \/>\n&lt;RunLevel&gt;HighestAvailable&lt;\/RunLevel&gt;<br \/>\n&lt;\/Principal&gt;<br \/>\n&lt;\/Principals&gt;<br \/>\n&lt;Settings&gt;<br \/>\n&lt;IdleSettings&gt;<br \/>\n&lt;Duration&gt;PT10M&lt;\/Duration&gt;<br \/>\n&lt;WaitTimeout&gt;PT1H&lt;\/WaitTimeout&gt;<br \/>\n&lt;StopOnIdleEnd&gt;true&lt;\/StopOnIdleEnd&gt;<br \/>\n&lt;RestartOnIdle&gt;false&lt;\/RestartOnIdle&gt;<br \/>\n&lt;\/IdleSettings&gt;<br \/>\n&lt;MultipleInstancesPolicy&gt;IgnoreNew&lt;\/MultipleInstancesPolicy&gt;<br \/>\n&lt;DisallowStartIfOnBatteries&gt;true&lt;\/DisallowStartIfOnBatteries&gt;<br \/>\n&lt;StopIfGoingOnBatteries&gt;true&lt;\/StopIfGoingOnBatteries&gt;<br \/>\n&lt;AllowHardTerminate&gt;true&lt;\/AllowHardTerminate&gt;<br \/>\n&lt;StartWhenAvailable&gt;false&lt;\/StartWhenAvailable&gt;<br \/>\n&lt;RunOnlyIfNetworkAvailable&gt;false&lt;\/RunOnlyIfNetworkAvailable&gt;<br \/>\n&lt;AllowStartOnDemand&gt;true&lt;\/AllowStartOnDemand&gt;<br \/>\n&lt;Enabled&gt;true&lt;\/Enabled&gt;<br \/>\n&lt;Hidden&gt;false&lt;\/Hidden&gt;<br \/>\n&lt;RunOnlyIfIdle&gt;false&lt;\/RunOnlyIfIdle&gt;<br \/>\n&lt;WakeToRun&gt;false&lt;\/WakeToRun&gt;<br \/>\n&lt;ExecutionTimeLimit&gt;P3D&lt;\/ExecutionTimeLimit&gt;<br \/>\n&lt;Priority&gt;7&lt;\/Priority&gt;<br \/>\n&lt;\/Settings&gt;<br \/>\n&lt;Actions Context=&#8221;Author&#8221;&gt;<br \/>\n&lt;SendEmail&gt;<br \/>\n&lt;Server&gt;192.168.0.1&lt;\/Server&gt;<br \/>\n&lt;Subject&gt;[Logon Notice] $(WorkstationName) has been accessed via RDP&lt;\/Subject&gt;<br \/>\n&lt;To&gt;admin@firm.com&lt;\/To&gt;<br \/>\n&lt;From&gt;server@firm.com&lt;\/From&gt;<br \/>\n&lt;Body&gt;RDP Login Successful<br \/>\nEventID: $(eventRecordID)<br \/>\nSystem: $(WorkstationName)<br \/>\nFrom: $(IpAddress)<br \/>\nBy: $(TargetUserName)&lt;\/Body&gt;<br \/>\n&lt;HeaderFields \/&gt;<br \/>\n&lt;\/SendEmail&gt;<br \/>\n&lt;\/Actions&gt;<br \/>\n&lt;\/Task&gt;<\/p><\/blockquote>\n<p>P.S.: mail server can be like: 192.168.0.1:28<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just edit and import XML-file into Task Scheduler. There is XML: &lt;?xml version=&#8221;1.0&#8243; encoding=&#8221;UTF-16&#8243;?&gt; &lt;Task version=&#8221;1.2&#8243; xmlns=&#8221;http:\/\/schemas.microsoft.com\/windows\/2004\/02\/mit\/task&#8221;&gt; &lt;RegistrationInfo&gt; &lt;Date&gt;2013-07-26T06:55:11.4860707&lt;\/Date&gt; &lt;Author&gt;Me&lt;\/Author&gt; &lt;Description&gt;Sends emails when server is accessed via RDP (Flag 10 &#8211; Remote connect).&lt;\/Description&gt; &lt;\/RegistrationInfo&gt; &lt;Triggers&gt; &lt;EventTrigger&gt; &lt;Enabled&gt;true&lt;\/Enabled&gt; &lt;Subscription&gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id=&#8221;0&#8243; Path=&#8221;Security&#8221;&amp;gt;&amp;lt;Select Path=&#8221;Security&#8221;&amp;gt;*[System[(EventID=4624)]] and *[EventData[Data[@Name=&#8217;LogonType&#8217;] and (Data=10)]]&amp;lt;\/Select&amp;gt;&amp;lt;\/Query&amp;gt;&amp;lt;\/QueryList&amp;gt;&lt;\/Subscription&gt; &lt;ValueQueries&gt; &lt;Value name=&#8221;IpAddress&#8221;&gt;Event\/EventData\/Data[@Name=&#8221;IpAddress&#8221;]&lt;\/Value&gt; &lt;Value name=&#8221;TargetUserName&#8221;&gt;Event\/EventData\/Data[@Name=&#8221;TargetUserName&#8221;]&lt;\/Value&gt; &lt;Value name=&#8221;WorkstationName&#8221;&gt;Event\/EventData\/Data[@Name=&#8221;WorkstationName&#8221;]&lt;\/Value&gt; &lt;Value name=&#8221;eventRecordID&#8221;&gt;Event\/System\/EventRecordID&lt;\/Value&gt; &lt;\/ValueQueries&gt; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,12],"tags":[],"class_list":["post-677","post","type-post","status-publish","format-standard","hentry","category-novosti","category-windows"],"_links":{"self":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=677"}],"version-history":[{"count":2,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/677\/revisions"}],"predecessor-version":[{"id":679,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/677\/revisions\/679"}],"wp:attachment":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}