Skip to content

Alerts not working #624

Closed Answered by c3s4rfred
catalinchertes asked this question in Q&A
Discussion options

You must be logged in to vote

Hi, @catalinchertes, first, check if the 'system' rules folder is present in the application, to do that, go to management rules right menu.

Then, if the folder is there, go to the log explorer top menu and select 'Windows', your logs should be there. After that, for example, generate 5 fail login attempts within 60 seconds, then in the log explorer -> 'Windows'. To raise for example a 'Password guessing alert' you must have at least 5 log records where 'logx.wineventlog.event_id' field's value is one of: 4625,529,530,531,532,533,534,535,536,537,539 and the value of field -> logx.wineventlog.event_data.TargetUserName is the same.

Let us know the results,
Best regards

Replies: 5 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by catalinchertes
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants