# AD - Winlogbeat - Consecutive failures to logon to specific set of computers

**URL:** <https://discuss.elastic.co/t/ad-winlogbeat-consecutive-failures-to-logon-to-specific-set-of-computers/138105>\
**Category:** Logstash\
**Created:** [July 1, 2018, 11:03pm UTC](https://discuss.elastic.co/t/ad-winlogbeat-consecutive-failures-to-logon-to-specific-set-of-computers/138105 "2018-07-01T23:03:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![spravveen](https://avatars.discourse-cdn.com/v4/letter/s/e8c25b/32.png) [@spravveen](https://discuss.elastic.co/u/spravveen)\
**Post date:** [July 1, 2018, 11:03pm UTC](https://discuss.elastic.co/t/ad-winlogbeat-consecutive-failures-to-logon-to-specific-set-of-computers/138105/1 "2018-07-01T23:03:55Z")

</div>

Hi,

I have an reporting / search requirement on Active Directory events. I am using winlogbeat to read events out of windows event log. Streaming these events to LogStash and further on to a log file and elasticsearch.

I have managed to search/report on few of the requirements. One req that I am having challenge with is, Consecutive failures to logon to a high value asset.

Can you please advise on how this could be done. Need to first classify specific systems connected to the domain as high value ones and then capture logon failures to these.

Thanks for the assistance.

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [July 2, 2018, 5:20am UTC](https://discuss.elastic.co/t/ad-winlogbeat-consecutive-failures-to-logon-to-specific-set-of-computers/138105/2 "2018-07-02T05:20:57Z")

</div>

We have something simliar set up but with watching all login failures on all server.

In the data from the winlogbeat there are the 4 fields

- event\_id
- event\_data.IpAddress
- event\_data.TargetUserName
- event\_data.Status

Search in the field event\_id for 4771 (see [Kerberos auth failed](https://www.ultimatewindowssecurity.com/securitylog/book/page.aspx?spid=chapter4))

Than you can filter for the ips of the hosts(event\_data.IpAddress) that interest you.

As a bonus in the field event\_data.TargetUserName is the username of the user that tried to login written and in the field event\_data.Status is written what has failed the auth.

- 0x18: Bad password
- 0x12: Account disabled, expired, locked out, logon hours restriction
- 0x25: Workstation's clock too far out of sync with DC's

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 3, 2018, 7:46pm UTC](https://discuss.elastic.co/t/ad-winlogbeat-consecutive-failures-to-logon-to-specific-set-of-computers/138105/3 "2018-07-03T19:46:36Z")

</div>

I agree with Shaoranlaos's suggestion. I actually have a saved search in Kibana for our desktop people to use that includes the fields he mentioned and I also have a transform on the event\_id field that links to [https://www.ultimatewindowssecurity.com](https://www.ultimatewindowssecurity.com)'s event description. If you are using Kibana, set the format to URL, Type to Link, and then use `https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID={{value}}` on the URL Template and `[[value]]` on the Label Template.

As a side note, if you want to identify any high value assets, you could tag events generated by them with an `if` in your pipeline and then use the `mutate` filter to add a tag or even an additional field if you wanted.

---

<div class="post-metadata">

**Author:** ![spravveen](https://avatars.discourse-cdn.com/v4/letter/s/e8c25b/32.png) [@spravveen](https://discuss.elastic.co/u/spravveen)\
**Post date:** [July 4, 2018, 11:06am UTC](https://discuss.elastic.co/t/ad-winlogbeat-consecutive-failures-to-logon-to-specific-set-of-computers/138105/4 "2018-07-04T11:06:18Z")

</div>

> [@Shaoranlaos](#):
>
> As a bonus in the field event\_data.TargetUserName is the username of the user that tried to login written and in the field event\_data.Status is written what has failed the auth.

This is awesome. Thanks a lot. I will give this a go.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2018, 11:17am UTC](https://discuss.elastic.co/t/ad-winlogbeat-consecutive-failures-to-logon-to-specific-set-of-computers/138105/5 "2018-08-01T11:17:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
