An administrator has been tasked to create a saved search that shows a list of multiple login failures for a
single user by username. The administrator has done the following:
1. Selected Last Hour in the view option.
2. In the Add filter window, selected the search parameter Custom Rule [Indexed].
3. Selected Equals for Operator.
4. Selected Authentication for Rule Group.
What is the next step the administrator needs to perform for the Rule option?
Currently there are no comments in this discussion, be the first to comment!