UBA : Multiple Sessions to Monitored Log Sources (NIS Directive)

QRadar® User Entity Behavior Analytics (UEBA) 앱은 특정 동작 이상 항목에 대한 규칙을 기반으로 하는 유스 케이스를 지원합니다.

UBA : Multiple Sessions to Monitored Log Sources (NIS Directive)

기본적으로 사용 가능

False

senseVaule 기본값

15

설명

5분 안에 단일 사용자의 동일한 QRadar 로그 소스 시스템에 2개 이상의 연결이 있는지 발견합니다.

지원 룰

BB:UBA : Common Event Filters

BB:CategoryDefinition: Authentication Success

필수 구성

다음 참조 세트에 적합한 값을 추가하십시오. "UBA : Monitored Log Sources (NIS Directive)".

로그 소스 유형

Linux OS(EventID: CRYPTO_LOGIN, ANOM_ROOT_TRANS, Accepted Password, GRP_AUTH, session opened, Privilege escalation, CRED_ACQ, Accepted Password, USER_LOGIN, Successful Login, password changed, LOGIN)

Microsoft Windows Security Event Log(EventID: Login succeeded for user, 18454, 193, 18455, 627, 4648, 1202, 680, 18453, 628, 621, 4624, 552, 672, 673_Attempt, 4672, 169, 10015, 10014, 678, 671, 6280, 4717, 4723, 4724, 540, 528, 673_Request, 673_Granted, 4776, 405, 5823, 1200, 682)