This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Domain Admin account lockout alert

Hello everyone,

I have an alert that tells me when an account is locked out. It works very nicely. Every once and a while it alerts me that my domain\administrator account is being locked out, but when I check that account it never is.

Has anyone seen this behavior?

Any ideas would be welcome!

Thanks!

  • LEM alerts you based on the events that it receives, so I would track it back:

    With the e-mail track it to the event and node that's alerting you, check the event in ndepth to make sure that it's there (it pretty well should be, but this can give you more information) and from there you can check the Tool Alias, Provider SID, Detection IP and so on to get you the log and information on the machine and I would check the local logs on that machine.

    If you aren't seeing the logs then I would suspect an issue with the rule correlation and double check that.

    If you see the event logged locally then that would explain why you're getting alerted, why it's being logged is another question entirely.

    Do you have a tool that will show you the history of the account? Do you have a policy that will unlock accounts automatically after a certain amount of time?  These can all provide clues as to what is actually going on.

  • A few times when I've had a rule go crazy I've rebuilt the rule and the issue fixed itself.

    Also, this might be obvious, but in group policy there is a setting for AD account auto-unlock period, I think the default is 30 minutes. I thought I'd bring this up just in case its getting auto unlocked before you have a chance to respond to your LEM Alert.