Are you running agents on your local machines? Do the agents read the appropriate logs (have connectors) for failed authentication attempts? Are your audit policies set to produce those log entries?
↧
Are you running agents on your local machines? Do the agents read the appropriate logs (have connectors) for failed authentication attempts? Are your audit policies set to produce those log entries?