A civic domain controller serving the courts OU is seeing a burst of failed logons. Which on-prem sourcetype should hold the brute-force evidence?
Select an answer to reveal the explanation.
Short Explanation
Failed logons on a courthouse DC live in Windows security logs—the same sourcetype every on-prem AD hunt starts with. Firewall syslog and DHCP leases are useful neighbors, but they are not the DC's attendance sheet. Match the evidence to the box that saw the attack.
Full Explanation
On-prem Active Directory brute force is typically recorded as Windows security events on the domain controllers, including failed-logon and lockout codes. Those events feed the Authentication data model once CIM-mapped. Edge-firewall syslog, DHCP leases, and unrelated Linux auth logs answer different questions and will miss the courts DC event codes. The analyst must pick the sourcetype that actually contains the evidence.