intrusion detection

S

Shayne D. Swann

Does anyone know of a tool that I can use to monitor the Security logs for
event ID 681's? I currently use event combmt to periododiclly monitor the
event logs for event ID 681,s. But this is some what ineffective for
proactivily monitoring for brut force attacks. We do not use MOM here (we
are too cheap). Is there a tool that I can use to report if X number of 681
per minute are flagged on a domain controller it will generate an email to
the domain admins?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top