HI guys!

i have an AD server where some linux servers authenticate with samba.
The thing is that looks like theres some trouble in the linux server
library and its causing kerberos validation trobules in the AD server,
so i get Rule: 18152 fired (level 10) -> "Multiple Windows Logon
Failures." all the time.
I dont want to modify the priority of that rule, but i do want to make
it more flexible, so i dont get 300 alerts in 1 nigth.


Any ideas?

Cheers!

Reply via email to