mirror of
https://github.com/amidaware/tacticalrmm.git
synced 2026-04-26 06:55:52 +03:00
[GH-ISSUE #66] Feature Request: Failed Logons #1977
Labels
No labels
In Process
bug
bug
dev-triage
documentation
duplicate
enhancement
fixed
good first issue
help wanted
integration
invalid
pull-request
question
requires agent update
security
ui tweak
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/tacticalrmm#1977
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @dan578 on GitHub (Aug 25, 2020).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/66
Originally assigned to: @wh1te909, @sadnub on GitHub.
Hi,
I know we can already check the log for event ID's so we can check for failed logon ID's. However it's not really customizable in the sense of 100 failed logon's in 24 hours would trigger the alert. Could this be added?
Thanks for all your work!
@wh1te909 commented on GitHub (Aug 25, 2020):
hi sorry just trying to understand the new feature, are you asking to be allowed to set a search period less than 24 hours like let's say only search the past 5 minutes of the log?
@dan578 commented on GitHub (Aug 25, 2020):
Hi, No problem I don't think I explained it well!
We would be looking for something like 500 events in 24 hours of the failed logon type.
(Event 4625) Which would be 500 failed logons.
I don't think its currently possible to specify how many of something should be or shouldn't be in the event logs? Just if it exists or doesn't.
Sorry does that make more sense?
Thanks
@wh1te909 commented on GitHub (Aug 25, 2020):
perfect yep makes sense now thanks! ok i'll work on this, will be in the next agent release. i'll update this ticket when it's done so you can test