How can I search for 10 failed logon attempts within a 5 minute timeframe?
I could try timechart, but a 24 hour period does not allow the interval to be as small as 5 mins. I could also "stats count by user", but this does not show any aspect of time.
Like this:
... | streamstats time_window=5m count(failed_logins) AS failed_logins BY user | where failed_logins >=10
@woodcock - Since he mentioned stats count by user
I think he wants ten failed logins for a single user...
No I'm actually looking for all failed logins by users. >10 was the most important part. Thanks
Updated, thank you @DalJeanis.
try this
| timechart span=5m count(failed_logins) as failed_logins | where failed_logins <=10
I think: s/</>/