1. 登陆失败相关信息/ m6 w5 O# @8 ~9 Z
事件ID: 46250 p9 h; I4 L( M& h7 R! i: ~
2.设置ITEM
" n8 B g" u* \9 c account logined attemp failer
# x. }# l8 h! Ikey: eventlog[Security,,Failure Audit,,^4625$,,skip]
2 A( V% ^( ]9 Z' }3.设置触发器
p9 e$ {# F. U' h9 aTrigger Name: User Login failer larger or equal three times
( m5 s# O K* y' a9 P
6 o! W. I; D. M2 d+ _+ F3 xProblem expression: {windows:eventlog[Security,,Failure Audit,,^4625$,,skip].count(180)}>=3" z9 h8 E! \* R* I
解释: 180秒内登陆失败3次,触发告警9 ^5 b5 e3 ?, ~$ y6 ?9 {
# M ~4 g! {- c) i |
评分
-
查看全部评分
|