Ad Widget

Collapse

Trigger after x amount of occurrences

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • eporro
    Junior Member
    • Dec 2021
    • 2

    #1

    Trigger after x amount of occurrences

    I have seen a lot of people ask about this and have tried all the suggestions but I am unable to get this to work.
    I am trying to cause a trigger if someone points in a wrong username or password on a Windows PC at least 4 times in the span of 3 minutes.

    The item is successfully getting the events. If I do a trigger with {Template - Windows OS:eventlog[Security,,,,4625,,skip].logeventid(4625)}=1 this triggers successfully.
    The trigger that is not working is {Template - Windows OS:eventlog[Security,,,,4625,,skip].count(180,4625)}>3

    Any idea what is wrong with my second trigger? I have cause more than 4 wrong username/password events but it never triggers.
  • tim.mooney
    Senior Member
    • Dec 2012
    • 1427

    #2
    This is just a guess, but it's the first thing that comes to mind.

    Because the 2nd argument to count() is purely numeric, and count() handles both numeric and text/log types, it may be treating it as a number, even though the eventlog[] item returns a log.

    I would try double-quoting the 4625 as the 2nd argument in count. If that doesn't work, try using the regexp feature of count(), and specify it as a regular expression.

    Comment

    • eporro
      Junior Member
      • Dec 2021
      • 2

      #3
      Since the value is always in the event, I don't need to search for it so instead I updated it to this and it works now: {Template - Windows OS:eventlog[Security,,,,4625,,skip].count(180)}>3

      Comment

      Working...