Create sentinel query

rahul haridas 0 Reputation points

Hi Please assist in creating a sentinel query for multiple login failures followed by a success for a user on a host in 1 hour duration. Here let say threshold is 15 . So the query should look for 16 failures followed by 1 success.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,057 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Clive Watson 5,951 Reputation points MVP

    You should be able to adapt a query like this one to your needs, personally I wouldn't limit the failures to a count (but I dont know your full use case).