Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Rules from a single host, from a single user ID

$
0
0

I need to create two rules that will alert on brute force attacks within specific time frame, one from the same source, and another one from the same user ID.

I see the rule "Continuous Excessive Logon Failures" template however I am unsure how to modify this rule to add the necessary parameter - from the same source.

These rules would be separate rules - IE one rule containing the same source, another rule containing the same user ID.

Any ideas would be appreciated.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>