I am quite new to splunk and I was wondering if it was possible to create a real time alert for locked account for a user and in the alert email the number of failed password attempts should be given for the user.
Thank you very much.
I would like to formulate something along the lines of correlating bad password attempts with locked accounts. Is that possible?
Look at this.
Locked account event tracing
failed login attempts
Locked account for which software? Maybe Active Directory Lockout alerts
In active directory lockout alerts, the search would only give me the locked accounts. Is there any way for the alert to show the failed login attempts made before the account gets locked out?