1 Reply Latest reply on Jul 28, 2013 7:23 PM by chris.jeffreys

    Destination Account does not equal Source Account


      Is there a way to do this?  I would like to create a rule where changes made to an account were not made by the user of that account.  I think this, along with other criteria, will get me what I want, but I don't know if it is possible to compare two fields to see if they are equal or not.

        • Re: Destination Account does not equal Source Account

          Yes, you can compare two fields and have a rule fire if those fields are not equal.  I've included an example of what I think you are trying to accomplish.


          1. Start by adding the Auditable Events (All).Source Account
          2. Drag Auditable Events (All).Destination Account into the empty field
          3. Change the condition to /=.


          I would suggest adding the additional Auditable Events (All).Source Account /= *$ to remove any machine account initiated changes such as account lockouts for too many logon failures.  There is a rule template that can be cloned if you want to be alerted on account lockouts.