# Watcher alerts for failed logons

**URL:** <https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517>\
**Category:** Elasticsearch\
**Created:** [July 10, 2017, 6:31pm UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517 "2017-07-10T18:31:40Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Izayuh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izayuh/32/19918_2.png) [@Izayuh](https://discuss.elastic.co/u/Izayuh)\
**Post date:** [July 10, 2017, 6:31pm UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/1 "2017-07-10T18:31:41Z")

</div>

I am currently using Winlogbeat to send security logs from multiple domain controllers. I want to set up a watcher alert that would trigger on x amount of failed logon attempts to the same user in a certain time range. Would anyone be able to help me with the query syntax for this certain case? Thanks.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 10, 2017, 9:16pm UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/2 "2017-07-10T21:16:15Z")

</div>

Hey,

unfortunately I dont have a windows machine to check how a failed login attempt looks like, are willing to share such a document? At the end, everything boils down to write a query, that matches your requirement and then put a watch around it...

--Alex

---

<div class="post-metadata">

**Author:** ![Izayuh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izayuh/32/19918_2.png) [@Izayuh](https://discuss.elastic.co/u/Izayuh)\
**Post date:** [July 11, 2017, 3:09pm UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/3 "2017-07-11T15:09:39Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/3X/c/e/ce3861ffb1f5408197fd9ed72ba41fb21ac45b69.png)

This is what the event itself looks like.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 12, 2017, 6:48am UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/4 "2017-07-12T06:48:36Z")

</div>

Hey,

I was talking about what the event looked like in Elasticsearch, not on the windows side. Can you just execute a search against the index that stores your event and show a sample JSON of a failed login attempt?

--Alex

---

<div class="post-metadata">

**Author:** ![Izayuh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izayuh/32/19918_2.png) [@Izayuh](https://discuss.elastic.co/u/Izayuh)\
**Post date:** [July 12, 2017, 3:11pm UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/5 "2017-07-12T15:11:03Z")

</div>

{  
"\_index": "winlogbeat-2017.07.12",  
"\_type": "wineventlog",  
"\_id": "AV03UyPKa8mW8Kx63QBo",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"computer\_name": "DCxxx",  
"process\_id": 496,  
"keywords": [  
"Audit Failure"  
],  
"log\_name": "Security",  
"level": "Information",  
"record\_number": "1288265xx",  
"event\_data": {  
"Status": "0x18",  
"PreAuthType": "2",  
"ServiceName": "krbtgt/",  
"TicketOptions": "0x4081001x",  
"TargetSid": "S-1-xxx",  
"IpAddress": "::ffff:xx.xx.x.xxx",  
"IpPort": "xxxxx",  
"TargetUserName": "xxx"  
},  
"message": "Kerberos pre-authentication failed.\n\nAccount Information:\n\tSecurity ID:\t\tS-1-xxx\n\tAccount Name:\t\xxx\n\nService Information:\n\tService Name:\t\tkrbtgt/xxx\n\nNetwork Information:\n\tClient Address:\t\t::ffff:xx.xx.x.xxx\n\tClient Port:\t\txxxxx\n\nAdditional Information:\n\tTicket Options:\t\t0x40810xx\n\tFailure Code:\t\t0x18\n\tPre-Authentication Type:\t2\n\nCertificate Information:\n\tCertificate Issuer Name:\t\t\n\tCertificate Serial Number: \t\n\tCertificate Thumbprint:\t\t\n\nCertificate information is only provided if a certificate was used for pre-authentication.\n\nPre-authentication types, ticket options and failure codes are defined in RFC 4120.\n\nIf the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present.",  
"opcode": "Info",  
"type": "wineventlog",  
"tags": [  
"beats\_input\_codec\_plain\_applied"  
],  
"thread\_id": 1300,  
"@timestamp": "2017-07-12T15:03:30.208Z",  
"task": "Kerberos Authentication Service",  
"event\_id": 4771,  
"provider\_guid": "{54849625-5478-4994-A5BA-3E3B0328C30D}",  
"@version": "1",  
"beat": {  
"hostname": "DCxxx",  
"name": "DCxxx",  
"version": "5.4.1"  
},  
"host": "DCxxx",  
"source\_name": "Microsoft-Windows-Security-Auditing"  
},  
"fields": {  
"@timestamp": [  
1499871810208  
]  
},  
"highlight": {  
"keywords": [  
"@kibana-highlighted-field@Audit Failure@/kibana-highlighted-field@"  
]  
},  
"sort": [  
1499871810208  
]  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 13, 2017, 7:59am UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/6 "2017-07-13T07:59:33Z")

</div>

Hey,

so in this example, you would need to build a query that filters for `ServiceName": "krbtgt/",` and searches in the `message` field for `kerberos failed`. Then this query also requires a filter for the last `n` minutes. As you also want to get counts per user, you need to have a `terms` aggregation on the `TargetUserName` field. The query would be something like this (I left out some parts, consider it pseudocode)

```auto
"query" : {
  "bool" : {
    "filter" : [
      { "range" : { "@timestamp" : { FROM NOW-5minutes TILL NOW } } },
      { "match" : { "message" : "kerberos failed" }}
    ]
  }
},
"aggs" : {
  "byUser" : {
     "terms" : { "field" : "TargetUserName" }   
} 
}

```

Once you have this query, you can start writing a watch. But make sure that the query works as expected.

For further alerting examples, check out the [examples repo](https://github.com/elastic/examples/tree/master/Alerting)

--Alex

---

<div class="post-metadata">

**Author:** ![Izayuh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izayuh/32/19918_2.png) [@Izayuh](https://discuss.elastic.co/u/Izayuh)\
**Post date:** [July 24, 2017, 4:05pm UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/8 "2017-07-24T16:05:22Z")

</div>

Thank you. After the usernames are bucketed how would I create a condition that would only return a hit if a bucket has 3 or more docs in it?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 25, 2017, 1:08pm UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/9 "2017-07-25T13:08:38Z")

</div>

Hey,

there is a `min_doc_count` parameter for the terms agg to only return buckets with a certain count, then you could check if any buckets are returned as part of the condition.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2017, 3:42pm UTC](https://discuss.elastic.co/t/watcher-alerts-for-failed-logons/92517/12 "2017-08-22T15:42:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
