cscli parsers install crowdsecurity/windows-auth
A parser for windows auth events read from the events log.
Only accepts events with from the Security channel with ID 4625.
1onsuccess: next_stage2#debug: true3filter: "evt.Parsed.Channel == 'Security' && evt.Parsed.EventID == '4625'"4name: crowdsecurity/windows-auth5description: "Parse windows authentication failure events (id 4625)"6statics:7 - meta: source_ip8 expression: XMLGetNodeValue(evt.Line.Raw, "/Event/EventData[1]/Data[@Name='IpAddress']")9 - meta: username10 expression: XMLGetNodeValue(evt.Line.Raw, "/Event/EventData[1]/Data[@Name='TargetUserName']")11 - meta: status12 expression: XMLGetNodeValue(evt.Line.Raw, "/Event/EventData[1]/Data[@Name='Status']")13 - meta: sub_status14 expression: XMLGetNodeValue(evt.Line.Raw, "/Event/EventData[1]/Data[@Name='SubStatus']")15 - meta: logon_type16 expression: XMLGetNodeValue(evt.Line.Raw, "/Event/EventData[1]/Data[@Name='LogonType']")17 - meta: log_type18 value: windows_failed_auth