Hi,
I'm trying to see the Invalid password from cisco asa events.
message_id=113005 | stats count by user | where count > 1
I try to count the number of failures by user and generate an alert for example in 5m the user fail the password 2times, but the alert is not trigger.
RealTime
Number of results is greater then 0 in 5minutes
Trigger for each result once.
Any idea whats the problem is?
Thanks
Its solved thanks, reboot splunk and started to work. Splunk was overloaded and wasnt processing the alerts.
Thanks
well, the query and alert is simple , it has to work. Are you sure that the time you checked / expected the alerts actually HAD any failures to set the trigger alert condition?