# Crete alerts for disabled accounts

**URL:** <https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833>\
**Category:** SIEM\
**Tags:** elastic-stack-alerting\
**Created:** [August 24, 2022, 5:48pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833 "2022-08-24T17:48:07Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajoshi37](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@ajoshi37](https://discuss.elastic.co/u/ajoshi37)\
**Post date:** [August 24, 2022, 5:48pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/1 "2022-08-24T17:48:07Z")

</div>

Hi,

I'm trying to create alerts for the Disabled account for Azure SSO but not able to find the context to that. Disabled account checks for event.code : 4725  
Failed account checks for event.code : "4625"

The logs do not show anything related to the disabled account. Is there a way the alerts can this can be accomplished?

Thanks.!!!!!!!

---

<div class="post-metadata">

**Author:** ![KristofC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kristofc/32/99589_2.png) [@KristofC](https://discuss.elastic.co/u/KristofC)\
**Post date:** [August 24, 2022, 7:02pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/2 "2022-08-24T19:02:16Z")

</div>

Hello @ajoshi37 , and thanks for reaching out to the community. I'm having a little difficulty understanding what you're trying to achieve, but it sounds like getting alert data from azure to show up in Kibana.

Have you successfully set up an Azure integration with Kibana, and if so which one? From the looks of your question Im guessing you'd be looking for this one:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/2949264182e6de3a9c97fb846bddd79056c33611.png)

/s/default/app/integrations/detail/azure-1.3.0/overview?integration=activitylogs

Which can be set up following the steps below

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/9/3931b1c0ea7f740a7b9bb10df5a3ff467116c8ed.jpeg)  
Click add integration from the main menu (very bottom left). Search for Azure, and find the right integration that you need.

Once this is configured you can create your own alerts by navigating to Alerts, manage rules:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6fcabb45ef3efc4e5870572940c38a0328027378.png)  
  

and from there creating your own rule based on whatever criteria you want. In your case a custom query of event.code : "4625" might be what youre looking for, but ensure that Kibana is querying the right indices or data view based on your Azure integration

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/3/631185a9fabe09cb5f4a01877e96281e7e0d550a.png).

  
If this isn't what youre trying to do, please provide somemore information and I'll try to figure it out with you.

---

<div class="post-metadata">

**Author:** ![ajoshi37](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@ajoshi37](https://discuss.elastic.co/u/ajoshi37)\
**Post date:** [August 24, 2022, 7:31pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/3 "2022-08-24T19:31:00Z")

</div>

Hi,

thanks for the follow-up. My alert is a little different.

We have Azure AD accounts which are disabled but we still use them for mailboxes/emails.  
I'm trying to create an alert for the failed login attempt for the disabled Azure AD account which was disabled by us.  
I'm not sure how to loop 2 Event.code into one alert.

Like first check for event.code : 4625 if only that matches than check for the event.code : "4725" for the same account.  
Like if the login was failed from any account than, after that check for the disabled account list if that's from the disabled account.  
But disabled account only have one event.code which is "4725" right.? Not sure how to implement that.

Hope I make sense now, thanks and let me know your thoughts.

---

<div class="post-metadata">

**Author:** ![KristofC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kristofc/32/99589_2.png) [@KristofC](https://discuss.elastic.co/u/KristofC)\
**Post date:** [August 24, 2022, 8:26pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/4 "2022-08-24T20:26:45Z")

</div>

Hey @ajoshi37 , Thanks for clarifying.

I'm wondering if you could go about it a different way. I'm not an Azure expert so feel free to correct me here, but what of doing a compound query for the failure to login alert.

Something like: `error_code: 4625 and result_description: *account disabled*`

The use of the asterisks would imply a partial match. So the query would look for failed login attempts based on the code 4625, and check that the result\_description field has something related to account being disabled. You could take it a step further and use the precise language of the result\_description, then the asterisks could be replaced with quotation marks.

Of course the fields may be named differently (event.code instead of error\_code for eg), but theoretically this should work.

Looking at a mock response:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9bec6b86ea379d65d9141dee2f6b357ae122cfa8.png)

---

<div class="post-metadata">

**Author:** ![KristofC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kristofc/32/99589_2.png) [@KristofC](https://discuss.elastic.co/u/KristofC)\
**Post date:** [August 25, 2022, 4:40pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/5 "2022-08-25T16:40:18Z")

</div>

@ajoshi37, I reached out to some other elasticians and they shared that it seems like you want a [sequence query](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql.html#eql-search-sequence). You could couple this with an event correlation query:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d0a248a0535f23d58b0aae460caec8cd6d07d717.png)

maybe something like:

```auto
sequence
  [event where event.code == "4725"]
  [event where event.code == "4625"]

```

---

<div class="post-metadata">

**Author:** ![ajoshi37](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@ajoshi37](https://discuss.elastic.co/u/ajoshi37)\
**Post date:** [August 25, 2022, 7:56pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/6 "2022-08-25T19:56:38Z")

</div>

Hi,

I tried using your suggested method but it was not successful for me.  
We disabled one account today and it was not showing in the below "Rule Preview" after I tried failed attempt for the account as I saw your updates on the case. I can see failed attempt for the same account in Azure and Elastic but not in the Rule preview after applying the query for today

 ![disbaled account](https://us1.discourse-cdn.com/elastic/original/3X/6/7/67caeb2b9fb50c2996e95fbce1f1c5d819031dab.png)  
.

I was not able to check the suggested query in Discover \< Logs\*. Is there a way I can test the query and then update you if that will that work or not.?

Thanks and let me know your thought.  
Apricate you are helping while as an Elastic Cloud Platinum member I was thrown at some docs which do not make any sense to this problem.

---

<div class="post-metadata">

**Author:** ![KristofC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kristofc/32/99589_2.png) [@KristofC](https://discuss.elastic.co/u/KristofC)\
**Post date:** [August 26, 2022, 1:49pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/7 "2022-08-26T13:49:33Z")

</div>

Can you share an entire event (the thing you truncated in your last picture on the left side. I want to see all the fields, feel free to hide the values if need be. Looks like since it's an EQL query it needs to match on an event category

```auto
sequence
  [event_category_1 where condition_1]  
  [event_category_2 where condition_2]

```

It kind of looks like your `category` field has the value `iam`

So you could maybe do:

```auto
sequence
  [iam where event.code == "4725"]  
  [iam where event.code == "4625"]

```

Send a better picture though so i can get a better look at your avaialble fields.

You can also test the query in your dev console:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/559ca3270804a28f0b7aaeaee7406b922f3c32dc.jpeg)

---

<div class="post-metadata">

**Author:** ![KristofC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kristofc/32/99589_2.png) [@KristofC](https://discuss.elastic.co/u/KristofC)\
**Post date:** [August 26, 2022, 1:56pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/8 "2022-08-26T13:56:43Z")

</div>

Heres an eg of runnning a sequence query in the dev console:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/b/abee49ba69c14b2187aa197c770ffb433ba4187f.jpeg)  
Note that Im using `behaviour` as the event category. I knew it would be possible as the events I have in my database have behavior as a value for category.

---

<div class="post-metadata">

**Author:** ![ajoshi37](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@ajoshi37](https://discuss.elastic.co/u/ajoshi37)\
**Post date:** [August 28, 2022, 1:52pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/9 "2022-08-28T13:52:34Z")

</div>

Hey,

I have attached the details of the log-in below screenshot with some of the private values changed.  
And I tried the query in the Dev tools as you suggested and got a valid response but not many details.

Thanks and let me know your thoughts.

 ![Dev tools Elastic](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e89810ef2696dfa84874dca804bc3a1e3fd3f61e.png)

 ![disbaled account 3](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7efbcbd87429d628aa311ad79347d163517005cf.png)  
 ![disbaled account 2](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e72e8bce005549fd0206656e44b4bd89e36858cd.png)  
 ![disbaled account 1](https://us1.discourse-cdn.com/elastic/original/3X/2/0/202c6f60abd5437da1e5453d7a44aabbeb5e34c0.png)

---

<div class="post-metadata">

**Author:** ![KristofC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kristofc/32/99589_2.png) [@KristofC](https://discuss.elastic.co/u/KristofC)\
**Post date:** [August 29, 2022, 4:57pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/10 "2022-08-29T16:57:26Z")

</div>

Looking at the sequence docs you need to use the **event category** to denote the sequence

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d3aa7e569011858da7767b19e94371ebfd9f12c5.png)

Your event category is "iam"

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b56034afe75af64263be65d5a10bd1a216e11813.png)

your query may look more like this:

```auto
sequence
  [iam where event.code == "4725"]  
  [iam where event.code == "4625"]

```

keyword above is `iam`. you may need to change the order though, meaning maybe 4625 first.

Can you send data for a 4625 event?

---

<div class="post-metadata">

**Author:** ![ajoshi37](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@ajoshi37](https://discuss.elastic.co/u/ajoshi37)\
**Post date:** [August 29, 2022, 6:48pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/11 "2022-08-29T18:48:40Z")

</div>

Hi, again.  
Thanks for the follow-up

There is no IAM event in 4625, the category for that is authentication (line 129). Attaching the screenshot for your reference.  
I tried the Query in Dev tools also with 4625 above but no luck, still the error.

 ![failed login 4](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f6255be054a0ab01d8049c5de8f6da43935e08ed.png)  
 ![failed login 3](https://us1.discourse-cdn.com/elastic/original/3X/2/6/26ac23831bf097f9fd8a521b78f403da9d02982c.png)  
 ![failed login 2](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bdec7fec1a4ed0618c5a4248bf93b644cbe7acf3.png)  
 ![failed login 1](https://us1.discourse-cdn.com/elastic/original/3X/6/0/6006463081a6f47260a2294752b7d13c49ac8c27.png)

Thanks and let me know your thoughts.

---

<div class="post-metadata">

**Author:** ![KristofC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kristofc/32/99589_2.png) [@KristofC](https://discuss.elastic.co/u/KristofC)\
**Post date:** [September 6, 2022, 4:05pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/12 "2022-09-06T16:05:35Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc51849cbb7f17eaa5ff92a68d9f4f7271ff15d5.png)

Do the two events happen right after each other? Or is the disabled one from way in the past? This might be problematic if so.

Is the data going to two different indices?

I see 1 index as `.ds-logs-system-security`, is this the index that both events get sent to?

If not you would need to create or use a [data view](https://www.elastic.co/guide/en/kibana/master/kibana-concepts-analysts.html#_accessing_data_with_data_views) to pool data from multiple sources. It looks like both events regardless of what indices they are, may be a part of your `default` data view so maybe that.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f85114d06b8f728add4b4497fdb156cdac0d8197.jpeg)

Though I am not certain of the order:

```auto
sequence
  [authentication where event.code == "4625"]  
  [iam where event.code == "4725"]

```

Will be closer to what youre looking for. With a consideration being a data view as mentioned above, and keeping in mind that this would work best if there is a usable time window. Meaning the disabled account events arent from 2 years ago, and the failed login attempt is yesterday, but rather when the failed login attempt happens, and triggers event A (bad login), another event- event B is also triggered soon after (disabled account), or vice versa. This way the sequence query has a small window of time to search.

---

<div class="post-metadata">

**Author:** ![ajoshi37](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@ajoshi37](https://discuss.elastic.co/u/ajoshi37)\
**Post date:** [September 7, 2022, 4:23pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/13 "2022-09-07T16:23:39Z")

</div>

I just did GET \_cat/indices/logs-\* and too many results came so, not sure which data stream they all going to.

These do not happen in a quick interval or it takes around 2-3 months to get the failed event details from the blocked account. It will be good if I can create that for some time, too.  
I just tested one for the disabled user and nothing showed up. (provided the wrong password for the disabled account)

Thanks and let me know.

---

<div class="post-metadata">

**Author:** ![KristofC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kristofc/32/99589_2.png) [@KristofC](https://discuss.elastic.co/u/KristofC)\
**Post date:** [September 8, 2022, 2:01pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/14 "2022-09-08T14:01:06Z")

</div>

Please try the following queries in dev tools:

```auto
GET .ds-logs-system-security/_eql/search
{
  "query": """
    authentication where event.code == "4625"
  """
}

```

```auto
GET .ds-logs-system-security/_eql/search
{
  "query": """
    iam where event.code == "4725"
  """
}

```

```auto
GET .ds-logs-system-security/_eql/search
{
  "query": """
    sequence
    [iam where event.code == "4725"]
    [authentication where event.code == "4625"]
  """
}

```

Also you can find your data views here in the Stack Management section of Kibana, and see which indices they include:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fd13aa4d2da54aa0ae1e7b26ed70312e85a20c1c.png)

---

<div class="post-metadata">

**Author:** ![ajoshi37](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@ajoshi37](https://discuss.elastic.co/u/ajoshi37)\
**Post date:** [September 9, 2022, 9:03pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/15 "2022-09-09T21:03:47Z")

</div>

HI,

I have saved the query and created the rule, but not seeing any alerts from that when I do a wrong password in the below screenshot but I see some output from the DEV tools.  
The DEV tool output is not tailored it throws bad password for today and blocked account details for 3 months before which is odd and they do not match.  
Like Alice wrong password today and Bob blocked account last month. (Has too many private information otherwise had attached a screenshot)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e37127c657308140de05c89e839cff7eba4e1388.png)

Thanks and let me know your thoughts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2022, 9:04pm UTC](https://discuss.elastic.co/t/crete-alerts-for-disabled-accounts/312833/16 "2022-10-07T21:04:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
