I want to create events for say, consecutive failed login from the same user, so i would use the query,
gl2_source_input: AND EventID:4771
And I would set search frequency, and Create Events for Definition if…‘Aggregation of results reaches a threshold’.
But how would I specify that these events are from the same user?
Any help would be appreciated.