Multiple Login Failures

Classification

Rule Name

Rule Type

Classification

Common Event

Multiple Login Failures

Base Rule

Security : Suspicious : Suspicious Activity

Suspicious Activity

Account Locked : Multiple Login Failures

Sub Rule

Authentication Failure

User Logon Failure : Account Locked Out

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text\String

N/A

<sip>

IP Address

N/A

<login>

Text\String

N/A

<process>

Text\String

N/A

<tag1>

Text\String

N/A

<Quantity>

Number