Elastic low stable eql

Unusual Login Activity

Identifies an unusually high number of authentication attempts.

View Source

Detection Logic

False Positives

  • Security audits may trigger this alert. Conditions that generate bursts of failed logins, such as misconfigured applications or account lockouts could trigger this alert.

Field Validations

Loading…

Comments (0)

Loading comments...