# Monitor Failed Log Ons EventID: 4625

**URL:** <https://community.graylog.org/t/monitor-failed-log-ons-eventid-4625/14350>\
**Category:** Graylog Central (peer support)\
**Created:** [March 5, 2020, 3:45pm UTC](https://community.graylog.org/t/monitor-failed-log-ons-eventid-4625/14350 "2020-03-05T15:45:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![michelledrew](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@michelledrew](https://community.graylog.org/u/michelledrew)\
**Post date:** [March 5, 2020, 3:45pm UTC](https://community.graylog.org/t/monitor-failed-log-ons-eventid-4625/14350/1 "2020-03-05T15:45:44Z")

</div>

I’ve managed to set an alert that gets triggered when a user fails its login 3 times in 1 minute (just test values). i get alerted. 1 minute later, the unresolved alert is solved and i didn’t even see it… please someone tell me how i can keep the unresolved alert up until i have checked it out and seen where it comes from etc… is there any way to get the unresolved alert written in a file so i can look at it when it’s been automatically resolved?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [March 6, 2020, 11:13am UTC](https://community.graylog.org/t/monitor-failed-log-ons-eventid-4625/14350/2 "2020-03-06T11:13:57Z")

</div>

you might want to read this part of the documentation:

[https://docs.graylog.org/en/3.2/pages/alerting/alerting-by-example.html](https://docs.graylog.org/en/3.2/pages/alerting/alerting-by-example.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 20, 2020, 11:14am UTC](https://community.graylog.org/t/monitor-failed-log-ons-eventid-4625/14350/3 "2020-03-20T11:14:00Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
