I have two thoughts:
First, it's possible that the machine that's "Detecting" the error is your Domain Controller, which hopefully doesn't have Active Response enabled. Perhaps you should try using UserLogonFailure.DestinationMachine for the agent?
Second, and a much simple possibility: Did you click the Activate Rules button after modifying, saving, and enabling the rule?