Primary User - Windows
Log In or Register to download the BES file, and more.

1 Votes

Versioning - This is the latest version.

1Primary User - Windows9/1/2015 11:59:19 AM
2Primary User - Windows1/25/2016 4:49:53 PM

Description

This analysis attempts to identify the Primary User of the system.

 


Property Details

ID2995831
StatusAlpha - Code that was just developed
TitlePrimary User - Windows
DomainBESC
Added by on 1/25/2016 4:49:53 PM
Last Modified by on 1/25/2016 4:49:53 PM
Counters 3143 Views / 101 Downloads
User Rating 1 star 2 star 3 star 4 star 5 star * Average over 1 rating. ** Log In or Register to add your rating.

Properties

PrimaryUser (Combined)
Period 12 hours
 
  * Results in a true/false
Show indented relevance
ERROR "NotYetWritten"
PrimaryUser Setting
Period 1 hour
 
  * Results in a true/false
Show indented relevance
unique values of (it as string as trimmed string) of values of settings whose("PrimaryUser" = name of it) of clients
User with most logons
Period 6 hours
 
  * Results in a true/false
Show indented relevance
unique values of names of users whose( logon count of it = maximum of logon counts of users )
Last Logged on User - Windows
Period 6 hours
 
  * Results in a true/false
Show indented relevance
unique values of items 1 of (modification time of it,name of parent folder of it) whose( item 0 of it = ( maximum of modification times of files "NTUSER.DAT" of folders whose ( exists file "NTUSER.DAT" of it AND name of it as lowercase is not contained by set of ( "networkservice";"localservice";"administrator";"default";"public";"la-client";"OTHER_EXCLUDED_USERS" ) ) of (folders "c:\users"; folders "c:\Documents and Settings") ) ) of files "NTUSER.DAT" of folders whose ( exists file "NTUSER.DAT" of it AND name of it as lowercase is not contained by set of ( "networkservice";"localservice";"administrator";"default";"public";"la-client";"OTHER_EXCLUDED_USERS" ) ) of (folders "c:\users"; folders "c:\Documents and Settings")
Users
Period 6 hours
 
  * Results in a true/false
Show indented relevance
("%22" & it & "%22") of concatenations "%22;%22" of unique values of (names of logged on users; names of users; names of current users; names of local users)
Users logged in (in BESClient Log - 30 days)
Period 12 hours
 
  * Results in a true/false
Show indented relevance
unique values of (preceding texts of lasts "'" of following texts of firsts "User interface process started for user '" of it) of lines whose(it contains "User interface process started for user '") of files whose( (exists lines of it) AND (name of it as uppercase ends with ".LOG") AND ( (name of it starts with ((it as string) of ( current year )) ) OR (name of it starts with ((it as string) of ( current year - 1*year )) ) ) ) of folders "__Global/Logs" of ((data folder of client)|(folder "/var/opt/BESClient/__BESData")|(folder "/Library/Application Support/BigFix/BES Agent/__BESData")|(folder "__BESData" of parent folder of client))
User with the most logins (in BESClient Log)
Period 1 day
 
  * Results in a "string"/number
Show indented relevance
(it) whose( multiplicity of it = maximum of multiplicities of unique values of (preceding texts of lasts "'" of following texts of firsts "User interface process started for user '" of it) of lines whose(it contains "User interface process started for user '") of files whose( (exists lines of it) AND (name of it as uppercase ends with ".LOG") AND ( (name of it starts with ((it as string) of ( current year )) ) OR (name of it starts with ((it as string) of ( current year - 1*year )) ) ) ) of folders "__Global/Logs" of (data folder of client) ) of unique values of (preceding texts of lasts "'" of following texts of firsts "User interface process started for user '" of it) of lines whose(it contains "User interface process started for user '") of files whose( (exists lines of it) AND (name of it as uppercase ends with ".LOG") AND ( (name of it starts with ((it as string) of ( current year )) ) OR (name of it starts with ((it as string) of ( current year - 1*year )) ) ) ) of folders "__Global/Logs" of (data folder of client)

Relevance

isWindows (Relevance 1172)
Used in 1113 fixlets and 524 analyses   * Results in a true/false
Show indented relevance
windows of operating system

Sharing

Social Media:
Share this page on Yammer

Comments

Log In or Register to leave comments!