All Apps and Add-ons

How can I see the invalid password attempts from Cisco ASA events?

sreis
Loves-to-Learn Everything

Hi,

I'm trying to see the Invalid password from cisco asa events.

message_id=113005 | stats count by user | where count > 1

I try to count the number of failures by user and generate an alert for example in 5m the user fail the password 2times, but the alert is not trigger.
RealTime
Number of results is greater then 0 in 5minutes
Trigger for each result once.

Any idea whats the problem is?
Thanks

0 Karma

sreis
Loves-to-Learn Everything

Its solved thanks, reboot splunk and started to work. Splunk was overloaded and wasnt processing the alerts.

Thanks

0 Karma

Sukisen1981
Champion

well, the query and alert is simple , it has to work. Are you sure that the time you checked / expected the alerts actually HAD any failures to set the trigger alert condition?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...