We have a requirement to audit all Applocker EXE and DLL events on all of our servers; how do I set up LEM to make this information available and prominent? We have our Group Policy configured to audit all Applocker (EXE and DLL) events in Windows. I've configured the connectors per server in LEM, but I need to know how to filter all Applocker events in LEM. I'm having a hard time associating Windows Events with LEM Events.
Any suggestions and/or guidance?