I need to have watcher enabled or machine learning enabled for this specific function.
I have a saved search in kibana named as – Windows Event ID - 4740 - Account Lockout
It is a filter for only the event id 4740 from winlogbeat.
I would like to know or get notified when a unique count of event_data.TargetUserName has more than 4 entries in 24 hours
The notification I would like to have notification from either watcher or machine learning with these fields if that particular criteria was met
Please do let me know how to create a watcher for this