All Apps and Add-ons

How can I see the invalid password attempts from Cisco ASA events?

sreis
Loves-to-Learn Everything

Hi,

I'm trying to see the Invalid password from cisco asa events.

message_id=113005 | stats count by user | where count > 1

I try to count the number of failures by user and generate an alert for example in 5m the user fail the password 2times, but the alert is not trigger.
RealTime
Number of results is greater then 0 in 5minutes
Trigger for each result once.

Any idea whats the problem is?
Thanks

0 Karma

sreis
Loves-to-Learn Everything

Its solved thanks, reboot splunk and started to work. Splunk was overloaded and wasnt processing the alerts.

Thanks

0 Karma

Sukisen1981
Champion

well, the query and alert is simple , it has to work. Are you sure that the time you checked / expected the alerts actually HAD any failures to set the trigger alert condition?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...