cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
kenn1
Level 7
Report Inappropriate Content
Message 11 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

Not entirely working yet. 

I am getting this to trigger, but it only seems to fire once a day. I want this to fire on EVERY ID that meets the criteria (say lockout signature) within a 24 hour time period. Not just 1 ID. I have a group by set up.

andy777
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 12 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

Here are some results from a test I configured today:

account-lockout-fire.PNG

It can take a few minutes since there is an interval for collecting the log, processing the log at the Receiver, collecting it from the Receiver, sending the events to the correlation engine and then collecting the events back plus the amount of time to duff the password and unlock the account.

Here is how my correlation rule is configured.

account-lockout-rule.PNG

kenn1
Level 7
Report Inappropriate Content
Message 13 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

Yes, but is it sending an alert for every ID that meets your threshold during a 24 hour period?

andy777
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 14 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

I just added an alarm and it appears to work. Here are the details of my configuration. Thanks.

alarrm2.PNG

alarrm3.PNG

alarrm4.PNG

alarrm5.PNG

alarmss.PNG

emails.PNG

kenn1
Level 7
Report Inappropriate Content
Message 15 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

Yes  - but did you get  alerts for multiple IDs over a 24 hour period?

andy777
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 16 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

Yes. That doesn't appear to be a factor. Thanks.

alarm6.PNG

rgarrett
Level 9
Report Inappropriate Content
Message 17 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

This won't affect what you are trying, but when you create an alarm based on a correlation event, you only need to select the ACE or the correlatioon data source.  Othewise, it wastes lots of processing power and is inefficient.

I would create a correlation rule based on the Normalization Rule Account Lockouts, with no parameters.  Make sure that fires.  Then g into the correlation rule, Go to the top (parameters) and add TimeWindow and Number of occurances.

Then you can create an alarm based on that correlation rule

T.

kenn1
Level 7
Report Inappropriate Content
Message 18 of 36

Re: Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

This is what I have. My problem is getting the alarm to trigger for each ID meeting the criteria over a 24 hour period.

1

kenn1
Level 7
Report Inappropriate Content
Message 19 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

Sorry - for some reason I cannot see the screen prints I am pasting in my browser. Not sure what happened.

andy777
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 20 of 36

Re: How Do I Create An Alert for a LAN Lockout Triggered Greater Than 10 times?

Concur. I'm unable to see them as well. If you are trying to copy and paste, you may need to save the file and use the Insert Image button.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community