Users Failing to Logon from Multiple IPs:
eventtype=msad-failed-user-logons (host="*")|fields _time,signature,src_ip,src_host,src_nt_host,src_nt_domain,user,Logon_Type | ip-to-host | fix-localhost |stats count by user,src_nt_domain,src_host,src_nt_host|stats count as nips by user,src_nt_domain|where nips>1|sort -nips|rename nips as "# Workstations", user as Username, src_nt_domain as "Domain"
Want: An email generated when count of IPs >1
Question: How to control the time interval? Real time alter when count >1 over the last 2 min?
... View more