
hhkyr (hhkyr) asked a question.
We are seeing several users get locked out of their accounts due to multiple failed login attempts from various countries. I'm curious if there is a field within the logs that display whether the credentials the attackers used were valid or not?
Knowing this information of course allows us to determine what additional actions we should take.
Is there a field value that we can look at to determine whether the password was correct or not?
Thanks!

Andrew,
You can look at the event info to see either case.
If you drill down you can see outcome with result, here is an example of a failure.