Alerting Best Practice documents
Posted: Tue Mar 08, 2016 2:55 pm
Are there any documents on best practices for alerting? By that I mean a single document that lists what would normally indicate things like accounts locked out, multiple bad password attempts, service failures, changes to Windows security policies, etc. and a threshold for sending the alerts. We, like I'd expect most organizations, have a mix of Windows & Linux systems.