Security-Related Queries for Windows

Comments

3 comments

  • Avatar
    Heidi Schaus

     Hi Mary, 

    Thank you for posting these - Do you know if there's a way, after turning this in to an alert, to filter out the count of affected machines? 

    For example, I have a machine that alerts at a given time with 5 login attempts in 15 minutes. In the next 15 minutes, we're up to 9, because 4 more attempts were made. I would want to be alerted on that first 5, but not the second wave of 4. I can't figure out how to make that work. 

    Do you have any suggestions? I'm not familiar with regex at all. 

    Thank you,

    Heidi 

    0
    Comment actions Permalink
  • Avatar
    Marie McGarry

    Hey Heidi, I'm not quite sure what the solution is.  I think it might be best for you to contact Sumo support on this one.  

    Regards,

    Marie 

    0
    Comment actions Permalink
  • Avatar
    Alex Norman

    Need more of these examples. These are great starting queries. 

    0
    Comment actions Permalink

Please sign in to leave a comment.