1. Describe your incident:
Hello everyone. I am trying to create an event which notifies me as soon as a user object in the AD is creating an amount of requests which is over a certain treshold (for example: I receive an e-mail if user object X has a message count of 50000 or higher shown in Graylog).
I cant seem to make it work and I am wondering if someone has created something similar and can share their search query with me.
2. Describe your environment:
Not applicable.
3. What steps have you already taken to try and solve the problem?
Tried to tinker with different winlogbeat search querys / Event IDs but couldnt find the correct way to make it work.
4. How can the community help?
Looking for help creating the correct search query.
Thanks in advance to everyone who is taking the time to help out!