The easiest way to get notified in real-time whenever a user attempts to log on more than X times with a wrong password is by forwarding “Microsoft-Windows-Security-Auditing” event 4625. This event is logged to the Security event log whenever a user fails to logon.
More information on event id 4625, including associated audit settings, is available on system32.eventsentry.com
Event Log: Security Severity: Audit Failure Source: Microsoft-Windows-Security-Auditing Category: Logon Event ID: 4625Manage your cookie preferences below:
To learn more about our use of cookies, please see our
Privacy Policy.