Security Compliance

Conditions for the default SEM Failed Logons filter

This article provides information about the conditions used for the default Failed Logons filter.

First published date

10/17/2018 5:52 PM

Last published date

10/17/2018 5:52 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).
This article provides the filter conditions used when filtering events on failed logons. 

 

Product section

Security Event Manager

Resolution

To access the filter in the SEM HTML5 console:
  1. Click the Events tab, and then expand the Authentication filter group
  2. Move your pointer over the Failed Logons filter to expose the vertical ellipsis.
  3. Click the vertical ellipsis, and then click Edit.

    The editable filter conditions appear in the filter builder.

     

You can also find the filter conditions in the SEM Flash console by clicking the Monitor tab, and then double-clicking the Failed Logons filter in the Authentication filter group.