Splunk Search

How to search failed login attempts of a user in Siteminder smaccess.log and alert after the 3rd unsuccessful login attempt?

krishnacasso
Path Finder

Need to develop a dashboard and a report for getting the the user information of who tried to log in and failed. Need to get an alert after the 3rd unsuccessful login attempt.

Thanks.

1 Solution

lguinn2
Legend

The following search will give you a list of user names (CN) that have more than 2 failed logins.

sourcetype=yoursourcetype  AuthReject
| stats count by CN
| where CN > 2

If you save this search as an alert, you can set the trigger condition to "number of results greater than zero".
You will need to identify the time range though: "number of failed login attempts in the last hour" is a very different thing than "number of failed login attempts in the past week."

View solution in original post

0 Karma

lguinn2
Legend

The following search will give you a list of user names (CN) that have more than 2 failed logins.

sourcetype=yoursourcetype  AuthReject
| stats count by CN
| where CN > 2

If you save this search as an alert, you can set the trigger condition to "number of results greater than zero".
You will need to identify the time range though: "number of failed login attempts in the last hour" is a very different thing than "number of failed login attempts in the past week."

0 Karma

lguinn2
Legend

Instead of hoping that someone in the community knows Siteminder, you could post a small portion of the log (with things like user names obfuscated). This would let many members answer your question...

0 Karma

lguinn2
Legend

Also it would be helpful to know what you used as a sourcetype, and the necessary field names.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...