Hi,
Does anyone have any SPL that looks at multiple logon failures utilizing event codes 672, 675, 676, 4768 and 4771? The parameters behind this query would be:
1.) Where client address is the same
2.) But the username is different
3.) Within X minutes
index=wineventlog sourcetype=* EventCode="672" OR "675" OR "676" OR "4768" OR "4771"
| table _time src user
index=wineventlog sourcetype=* EventCode="672" OR "675" OR "676" OR "4768" OR "4771"
| stats values(username) as usernames, dc(username) as user_num by src_ip
| where user_num > 1
Above should work, just make sure there is a src_ip on your data otherwise change it to the desired IP field
Add this to the end of your query
|timechart dc(user) as failedUsers by src span=15m|where failedUsers>1
Does that get you close to what you are after?