Daily reports Postilion
Alarms - A05W063 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05W063
Alarms - A05L020 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05L020
Alarms - A05W067 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05W067
Alarms - A05W068 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05W068
Alarms - A05W069 from: 2018-10-27 to: 2018-10-27
Alarm Risk Source Destination
Delivery & Attack - Bruteforce Authentication - Cisco ACS 1 A05W069 0.0.0.0
(5 events)
Alarms - A05W070 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05W070
Alarms - A05L015 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05L015
Alarms - A05L016 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05L016
Alarms - A05L017 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05L017
Alarms - A05L019 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05L019
User: admin / 2018-10-29 07:24:47 Page 1 / 6
Daily reports Postilion
Alarms - a03l020 from: 2018-10-27 to: 2018-10-27
No Alarms Found for a03l020
Alarms - A05W065 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05W065
Alarms - I05W002 from: 2018-10-27 to: 2018-10-27
No Alarms Found for I05W002
Alarms - I05L001 from: 2018-10-27 to: 2018-10-27
No Alarms Found for I05L001
Alarms - I05L002 from: 2018-10-27 to: 2018-10-27
No Alarms Found for I05L002
Alarms - I05L000 from: 2018-10-27 to: 2018-10-27
No Alarms Found for I05L000
Alarms - I05W003 from: 2018-10-27 to: 2018-10-27
No Alarms Found for I05W003
Alarms - A01W031 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A01W031
Alarms - A01W024 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A01W024
Alarms - A00W195 from: 2018-10-27 to: 2018-10-27
User: admin / 2018-10-29 07:24:47 Page 2 / 6
Daily reports Postilion
Alarm Risk Source Destination
Delivery & Attack - Bruteforce Authentication - Cisco ACS 2 A00W195 0.0.0.0
(90 events)
Delivery & Attack - Bruteforce Authentication - Cisco ACS 2 A00W195 A03L012
(90 events)
Alarms - I05W001 from: 2018-10-27 to: 2018-10-27
No Alarms Found for I05W001
Alarms - A05W060 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05W060
Alarms - A05W061 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05W061
Alarms - A05W062 from: 2018-10-27 to: 2018-10-27
No Alarms Found for A05W062
Alarm events - Alarm events. Last 25 Events: from: 2018-10-27 to: 2018-10-27
Event Name Date GMT+2:00 Source Destination Risk
directive_event: AV Bruteforce attack, login
2018-10-27 22:52:09 A00W195 0.0.0.0
authentication attack against 192.168.179.10
directive_event: AV Bruteforce attack, login
2018-10-27 22:52:08 A00W195 A03L012:49
authentication attack against 192.168.179.10
directive_event: AV Bruteforce attack, login
2018-10-27 22:52:08 A00W195 0.0.0.0
authentication attack against 192.168.179.10
directive_event: AV Bruteforce attack, login
2018-10-27 22:52:08 A00W195 A03L012:49
authentication attack against 192.168.179.10
directive_event: AV Bruteforce attack, login
2018-10-27 22:48:58 A05W069 0.0.0.0
authentication attack against 10.20.20.17
AlienVault HIDS: SSH insecure connection
2018-10-27 22:25:38 192.168.116.11 I05L002
attempt (scan).
User: admin / 2018-10-29 07:24:47 Page 3 / 6
Daily reports Postilion
AlienVault HIDS: SSH insecure connection
2018-10-27 22:25:36 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 22:15:26 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 21:50:01 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 21:44:56 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 21:39:56 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 21:34:59 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 21:05:16 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 20:59:46 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 20:49:44 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 19:44:46 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 19:39:31 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 19:25:34 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 19:21:30 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 19:05:04 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 19:02:44 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 19:02:42 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 18:50:22 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 18:50:20 192.168.116.11 I05L002
attempt (scan).
AlienVault HIDS: SSH insecure connection
2018-10-27 18:50:19 192.168.116.11 I05L002
attempt (scan).
Logins - Logins. Last 25 Events: from: 2018-10-27 to: 2018-10-27
Date
Event Name Device IP Username Source Dest.
GMT+2:00
2018-10-27 PassedAuth: Cisco ACS
192.168.110.20 UCS_Admin A00W195 A03L012:49
22:52:16 passed authentications.
2018-10-27 PassedAuth: Cisco ACS
192.168.110.20 UCS_Admin A00W195 A03L012:49
22:52:14 passed authentications.
2018-10-27 PassedAuth: Cisco ACS
192.168.110.20 UCS_Admin A00W195 A03L012:49
22:52:13 passed authentications.
User: admin / 2018-10-29 07:24:47 Page 4 / 6
Daily reports Postilion
2018-10-27 PassedAuth: Cisco ACS
192.168.110.20 UCS_Admin A00W195 A03L012:49
22:52:13 passed authentications.
2018-10-27 PassedAuth: Cisco ACS
192.168.110.20 UCS_Admin A00W195 A03L012:49
22:52:10 passed authentications.
2018-10-27 PassedAuth: Cisco ACS
192.168.110.20 UCS_Admin A00W195 A03L012:49
22:52:09 passed authentications.
2018-10-27 PassedAuth: Cisco ACS
192.168.110.20 UCS_Admin A00W195 A03L012:49
22:52:09 passed authentications.
2018-10-27 PassedAuth: Cisco ACS
192.168.110.20 UCS_Admin A00W195 A03L012:49
22:52:08 passed authentications.
AlienVault HIDS:
2018-10-27
Successful login during 192.168.153.11 swmu A00W195:56323 A07L004
22:46:23
non-business hours.
AlienVault HIDS:
2018-10-27
Successful login during 192.168.179.10 SYSTEM A00W195 A00W195
22:46:23
non-business hours.
AlienVault HIDS:
2018-10-27
Successful login during 192.168.179.10 SYSTEM A00W195 A00W195
22:46:23
non-business hours.
AlienVault HIDS: Special
2018-10-27
privileges assigned to new 192.168.179.10 SYSTEM A00W195 A00W195
22:46:23
logon
AlienVault HIDS: Special
2018-10-27
privileges assigned to new 192.168.179.10 SYSTEM A00W195 A00W195
22:46:23
logon
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:23
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:23
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:23
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:23
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:23
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:23
AlienVault HIDS:
2018-10-27
Windows Network Logon 10.20.20.15 A05W063$ A05W063:49487 A05W067
22:46:13
AlienVault HIDS:
2018-10-27
Windows Network Logon 10.20.20.15 A05W063$ A05W063:49487 A05W067
22:46:13
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:05
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:05
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:05
AlienVault HIDS:
2018-10-27
Windows Network Logon 192.168.179.10 A00W125$ 0.0.0.0 A00W195
22:46:05
Cleartext - Cleartext. Last 25 Events: from: 2018-10-27 to: 2018-10-27
No data available
FTP Failed Logons - FTP Failed Logons. Last 25 Events: from: 2018-10-27 to: 2018-10-27
No data available
PCI - Protect Stored Data - Database Succesful Logins. Last 25 Events: from: 2018-10-27 to: 2018-10-27
No data available
User: admin / 2018-10-29 07:24:47 Page 5 / 6
Daily reports Postilion
Custom Security Events - Windows User Logons. Last 25 Events: from: 2018-10-27 to: 2018-10-27
No data available
User: admin / 2018-10-29 07:24:47 Page 6 / 6