I am trying to create an alert that will tell me when a login fails X number of times in Y seconds due to bad credentials. I have the alert working by looking at event log entries, but if a second login fails, it "updates" the alert with the new account information and details from the event log. Is there any way to stop this from happening? Ideally, a second alert would be created. I think part of the problem is that the source and name remain the same.
I am using a monitor to do this, not a rule. --- *Andrew Sanders* | *Enterprise Systems Specialist * Enterprise Systems | Information Technology Services | Appalachian State University 828-262-7803 (p) | 828-262-6034 (f) | [email protected] Peacock Hall - Rm 1127 | 416 Howard St. | Boone, NC | 28608 http://cio.appstate.edu | http://its.appstate.edu | http://support.appstate.edu Microsoft Certified IT Professional | Microsoft Certified Technical Specialist Need Help? Enter a Support Request at http://support.appstate.edu/help
