Issue answer with 1.3

I have done and sure that my answer is correct when I filter rule.id, rule.name, rule.group to check the total number of login atttempt of a non-exixting user,
but the answer still reveal wrong. what is it ?

( 2. What was the total number of login attempts for a non-existent user?)

Please provide the name of the lab when asking for help :slight_smile:

Lab name : 1.3 challenge Exercise
Module 1 SIEM basic,
Level 3

When I use the correct filter, I get the correct number of events:

Remember we are looking for logins from a “non-existent user”. Seems like the verbiage is important.

1 Like

thank you for support!

1 Like