wanted to share a real-world scenario I recently encountered regarding Prism Central account lockouts and see how the community handles similar setup challenges.
The Issue:
Our primary local administrator account on Prism Central kept getting locked out unexpectedly. After inspecting the logs, we traced the issue to an external automated log integration (like a SIEM/Splunk collector) executing API calls using stale credentials.
Even after disabling the integration at the source and resetting the admin password, the lockout behavior occasionally persisted due to cached sessions or residual background API requests.
