1. 登陆失败相关信息4 ]9 p- R) o( h
事件ID: 4625
* T- [. O* q! s2.设置ITEM5 k, O' B- L, e& e5 z$ V1 T
account logined attemp failer8 _* Y3 ^, Y' O1 M# F4 ~
key: eventlog[Security,,Failure Audit,,^4625$,,skip]
$ e) ^: k: v6 J, q3.设置触发器5 R( m( q* T. B( w i+ b: B
Trigger Name: User Login failer larger or equal three times7 e( b7 K! R9 J
3 L5 c6 B) O) e4 u* ?! V: x
Problem expression: {windows:eventlog[Security,,Failure Audit,,^4625$,,skip].count(180)}>=3
% S' g, h* d4 n' }5 Z* p% u 解释: 180秒内登陆失败3次,触发告警2 [8 }7 |2 v" |1 V' c1 C8 s# W0 h7 K
7 l& }! g" [' E' E) r: t2 ~2 X9 S |
评分
-
查看全部评分
|