A security administrator notices that a specific user is generating excessive logs due to repeated authentication failures. The administrator wants to see only failed authentication events for that user in the monitor tab. Which filter string should be used in the log viewer?
Trap 1: (addr.src eq user@domain.com) or (eventid eq auth-fail)
The or operator returns every event matching either condition, so all traffic from that address appears alongside failed authentications from any user. It is tempting because both terms are relevant, but and is required to intersect the user with the auth-fail eventid and isolate the failures.
Trap 2: (addr.src eq user@domain.com) and (severity ge medium)
Severity medium does not correspond to authentication failure; it captures unrelated medium-and-above events for that address, missing auth failures logged at lower severity. Filtering by severity is tempting for triage, but the eventid auth-fail field identifies the specific event type required here.
Trap 3: (src eq user@domain.com) and (eventid eq auth)
The src field does not hold the user identity in this log schema, and eventid eq auth matches successful authentications rather than failures. Using src and a generic auth eventid is tempting because both look user- and auth-related, but the correct fields are addr.src and eventid auth-fail.
- A
(addr.src eq user@domain.com) or (eventid eq auth-fail)
Why it fails: The or operator returns every event matching either condition, so all traffic from that address appears alongside failed authentications from any user. It is tempting because both terms are relevant, but and is required to intersect the user with the auth-fail eventid and isolate the failures.
- B
(addr.src eq user@domain.com) and (severity ge medium)
Why it fails: Severity medium does not correspond to authentication failure; it captures unrelated medium-and-above events for that address, missing auth failures logged at lower severity. Filtering by severity is tempting for triage, but the eventid auth-fail field identifies the specific event type required here.
- C
(addr.src eq user@domain.com) and (eventid eq auth-fail)
Correctly combines user and auth-fail event.
- D
(src eq user@domain.com) and (eventid eq auth)
Why it fails: The src field does not hold the user identity in this log schema, and eventid eq auth matches successful authentications rather than failures. Using src and a generic auth eventid is tempting because both look user- and auth-related, but the correct fields are addr.src and eventid auth-fail.