Hi,
Do you know if there is any way to exclude from rule "Multiple Login Failures to the Same Destination" domain controllers, but not to miss any suspicious events?
I have a lot of f/p events form workstations joined to AD and its hard to see any suspicious.
#QRadar#Support#SupportMigration