Link to home
Start Free TrialLog in
Avatar of FphcareAdmins
FphcareAdmins

asked on

SCOM monitor - detection logon failure attempts in one hour

Hi

Anyone know how to create the detection monitor on scom.

we want to detect if account logon failure attempts count 15 times in one hour on any computers, then it will send a notification email.

this monitor will apply to windows 2003 and windows 2008.

THanks
Alex
Avatar of maqsoodjee
maqsoodjee

Go Authoring Pane and create a new monitor. Create a Repeated Event Detection monitor to detect failure logon events. Target your domain controllers.
You should also take a look at the ACS feature of Ops Mgr,
ASKER CERTIFIED SOLUTION
Avatar of maqsoodjee
maqsoodjee

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of FphcareAdmins

ASKER

Thanks for the reply, but your monitor will only monitor login on AD. We want to monitor all login on all device such as stand server (it is in same doamin). I can see the logs on security events.

for the test, I have change the target to all windows 2008 computers and change count to 2 with 1minute.

run the test, i can see the failed logon happens on 4 times in 1 minute but no alerts happen.