Question 1hardmultiple choice
Read the full Log Management and SIEM explanation →GSEC Log Management and SIEM • Complete Question Bank
Complete GSEC Log Management and SIEM question bank — all 0 questions with answers and detailed explanations.
{
"timestamp": "2023-10-27T14:32:10Z",
"event_id": 4624,
"logon_type": 3,
"source_ip": "192.168.100.50",
"target_user": "jsmith",
"authentication_package": "NTLM",
"failure_reason": "N/A"
}Jun 14 08:12:35 authsrv sshd[4521]: Accepted publickey for root from 10.0.0.15 port 54321 ssh2: RSA SHA256:abc123xyz Jun 14 08:14:02 authsrv sudo[4810]: jsmith : TTY=pts/0 ; PWD=/home/jsmith ; USER=root ; COMMAND=/bin/bash
2023-10-12T14:22:01Z [WARN] Failed login from 192.168.1.55 on host SRV-01 2023-10-12T14:22:02Z [WARN] Failed login from 192.168.1.55 on host SRV-01 2023-10-12T14:22:03Z [WARN] Failed login from 192.168.1.55 on host SRV-01 2023-10-12T14:22:04Z [WARN] Failed login from 192.168.1.55 on host SRV-01