Determining failed administrator interface logons from syslog
Hello!I'm running into an issue. I would like to record failed logons to the administrator interface via syslog but the log format and contents of the logs appear to be exactly the same as those when a user performs a failed login to GlobalProtect Client VPN. Therefore I am getting a bunch of false positives.Has anyone had any luck with this?




