You should be able to adapt a query like this one to your needs, personally I wouldn't limit the failures to a count (but I dont know your full use case).
Create sentinel query
rahul haridas
0
Reputation points
Hi Please assist in creating a sentinel query for multiple login failures followed by a success for a user on a host in 1 hour duration. Here let say threshold is 15 . So the query should look for 16 failures followed by 1 success.
Microsoft Security | Microsoft Sentinel
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
1 answer
Sort by: Most helpful
-
Clive Watson 7,946 Reputation points MVP Volunteer Moderator2023-06-01T08:26:37.4433333+00:00