Security

Basic Brute Force Detection (Splunk Security Essentials)

jamie1
Communicator

Hi There,

I am new to Splunk and have data coming in from just one server. I have tried running the basic brute force detection search, and receive thousands of events. I don't think this is accurate and thus feel as though I must have misconfigured something, somewhere. I'm not sure where I should begin to look.

Any help would be appreciated,

Jamie

Labels (1)
0 Karma

jamie1
Communicator

I also noticed an error: (Eventtype 'bd_Authentication-audit' does not exist or is disabled).

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...