Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Multiple Failed Login attempts by different users but same IP

$
0
0

Just to backup HolyGuacamole with some pictures:

 

You'd want a rule that was at least this complicated:

 

2014-06-18 07_45_45-SolarWinds Log and Event Manager Console.png

The circled thing is what Guac is referring to.  Then you can do this:

2014-06-18 07_46_13-SolarWinds Log and Event Manager Console.png

 

And that means the LEM has to see 5 events in 30 seconds from the same DetectionIP.  You can obviously use other fields as well if you want to play with it.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>