# Spike in failed logon events ML rule alerting

**URL:** <https://discuss.elastic.co/t/spike-in-failed-logon-events-ml-rule-alerting/327642>\
**Category:** Elastic Security\
**Created:** [March 14, 2023, 9:31am UTC](https://discuss.elastic.co/t/spike-in-failed-logon-events-ml-rule-alerting/327642 "2023-03-14T09:31:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maretti/32/118976_2.png) [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Post date:** [March 14, 2023, 9:31am UTC](https://discuss.elastic.co/t/spike-in-failed-logon-events-ml-rule-alerting/327642/1 "2023-03-14T09:31:53Z")

</div>

Hi everyone

I am experimenting with the ML learning rule that alerts when a spike happens in failed logon events. I did a RDP bruteforce from kali to windows in the bruteforce the password did get guessed so the host is actually compromised. The alert just gives a low severity alert so it would be better if another alert gets send if a successful logon happened during the spike.

> **[Spike in Failed Logon Events | Elastic Security Solution \[master\] | Elastic](https://www.elastic.co/guide/en/security/master/spike-in-failed-logon-events.html)**

What would be an easy way to do this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2023, 9:32am UTC](https://discuss.elastic.co/t/spike-in-failed-logon-events-ml-rule-alerting/327642/2 "2023-04-11T09:32:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
