I have a WMI sensor configured to log Security Audit Failures. From time to time it appears to report literally billions of new records (volume) but the actual event log on the windows server this sensor is monitoring has no login failure events.
Is there a bug in this sensor or could it be misconfigured? I'm unsure how to upload screenshots here so apologies for the lack of images.
Add comment