UBA : Multiple Sessions to Monitored Log Sources (NIS Directive)
QRadar® User Entity Behavior Analytics (UEBA) 앱은 특정 동작 이상 항목에 대한 규칙을 기반으로 하는 유스 케이스를 지원합니다.
UBA : Multiple Sessions to Monitored Log Sources (NIS Directive)
기본적으로 사용 가능
False
senseVaule 기본값
15
설명
5분 안에 단일 사용자의 동일한 QRadar 로그 소스 시스템에 2개 이상의 연결이 있는지 발견합니다.
지원 룰
BB:UBA : Common Event Filters
BB:CategoryDefinition: Authentication Success
필수 구성
다음 참조 세트에 적합한 값을 추가하십시오. "UBA : Monitored Log Sources (NIS Directive)".
로그 소스 유형
Linux OS(EventID: CRYPTO_LOGIN, ANOM_ROOT_TRANS, Accepted Password, GRP_AUTH, session opened, Privilege escalation, CRED_ACQ, Accepted Password, USER_LOGIN, Successful Login, password changed, LOGIN)
Microsoft Windows Security Event Log(EventID: Login succeeded for user, 18454, 193, 18455, 627, 4648, 1202, 680, 18453, 628, 621, 4624, 552, 672, 673_Attempt, 4672, 169, 10015, 10014, 678, 671, 6280, 4717, 4723, 4724, 540, 528, 673_Request, 673_Granted, 4776, 405, 5823, 1200, 682)