Alerting

get the number of failed logins to 1 device in the time span of 1 minute - Brute Force and Spray attacks

Alfred
Explorer

Brute Force and Spray attacks - use case 

1- Multiple accounts failed logon from the same IP - within 1 minute

2- Single account failed logon from multiple hosts - in 1 minute

3- 1 user account failed to  log to 3 hosts destination - in 2 minutes

 

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...