Hi All, Is there a filter, in the Meraki event logs, which would identify any/all connections that have been made via RDP? A computer on the network in question was running RDP on the standard port via port forwarding, and I'm trying to determine if/when anyone was connecting to it via that method because a user's Gmail account was breached and I'm trying to figure out how that occurred when 2FA is enabled on the account. Wondering if somebody lucked out and came across the IP and subsequently found the workstation in an unlocked state. Seems unlikely, but I'd like to track who's been connecting in. Thanks in advance...
... View more