Scenario: You received an alert just like the one we built yesterday about multiple failed logins.

Your task is to use KQL to answer the following:

Report Template

Notes:

Logs Date

4/16/2021, 8:34:04.098 AM - 4/16/2021, 9:33:42.146 AM

Which accounts are experiencing the most failed logons?

\ADMINISTRATOR has a total 10255 failed login.