IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

I got many alerts: "Multiple Login Failures for the Same User containing Failure Audit: An account failed to log on"

  • 1.  I got many alerts: "Multiple Login Failures for the Same User containing Failure Audit: An account failed to log on"

    Posted Wed February 08, 2023 11:26 PM
    Edited by Anh Minh Wed February 08, 2023 11:27 PM

    Good morning everyone! 

    At the moment I'm getting this problem, My SIEM Qradar generated many alerts which user is fail to login to a FILESERVER: "Multiple Login Failures for the Same User containing Failure Audit: An account failed to log on". 

    I confirmed with users that there's no login failed behavior from them. 

    I tried myself to login to the FILESEVER, login sucessfully at the first time (and only one time), but also get the login failures offense. 

    If anyone got the same issue, please help me to explain this? 

    Thank you so much!



    ------------------------------
    Anh Minh
    ------------------------------



  • 2.  RE: I got many alerts: "Multiple Login Failures for the Same User containing Failure Audit: An account failed to log on"

    Posted Thu February 09, 2023 05:10 AM

    Thank you so much for reading! 

    I solved my problem. 

    Have a great day!



    ------------------------------
    Anh Minh
    ------------------------------



  • 3.  RE: I got many alerts: "Multiple Login Failures for the Same User containing Failure Audit: An account failed to log on"

    Posted Tue February 14, 2023 06:51 AM

    Hi,

    May I know how you resolved?



    ------------------------------
    Arunkumar R
    ------------------------------



  • 4.  RE: I got many alerts: "Multiple Login Failures for the Same User containing Failure Audit: An account failed to log on"

    Posted Mon November 06, 2023 07:47 AM

    Hi @Anh Minh

    Can you share what was the solution?

    Regards,



    ------------------------------
    DCS Feeds
    ------------------------------