I'm Exploring ELK as a SIEM. As a beginner I have Winlogbea installed on a virtual machine that's subscribed to forwarded events from Domain Controller. I've made subsequent changes to the YML file and I'm receiving the logs within elastic. ** ISSUE: 0 FAILED AUTHENTICATION ** Please view the attached image and let me know if have to make changes in GPO or YML file to get failed logs.
Hi Andrew,
The test config came ok. But still not getting failed authentications in SIEM, while in discover tab I was able to find different failed logon events. I've created a work around to visualize failed auths in dashboards until I figure out how to get failed authentication on elastic SIEM.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.