    Correlation rule for logons to other PCs


      I have a simple list of users with their authorized hosts

      User A; Host A

      User B; Host B



      I am trying to build a rule where in an ideal scenario and email would be fired upon the following scenario: User A logs with his Windows credentials to the PC of User B.


      I understand maybe this can be done with combining two or more User Defined Groups, but I am looking if someone has implemented anything similar.