Alerting

How to compare a field found in 2 different event codes?

zuyi21
New Member

Hi, i would like to create alert.
Condition:
match Account name(New account) in eventcode 4720 with Account name(member) in eventcode 4728.

Below is how the log looks like:

Event code 4720:
Subject:
Security ID: S-1-5-21-97631821-2522574050-3878054474-500
Account Name: administrator
Account Domain: ABC
Logon ID: 0x6a7a0
New Account:
Security ID: S-1-5-21-97631821-2522574050-3878054474-1118
Account Name: T1
Account Domain: ABC

Event code 4728:
Subject:
Security ID: S-1-5-21-97631821-2522574050-3878054474-500
Account Name: administrator
Account Domain: ABC
Logon ID: 0x6a7a0
Member:
Security ID: S-1-5-21-97631821-2522574050-3878054474-1118
Account Name: cn=T1,CN=Users,DC=abc,DC=com
Group:
Security ID: S-1-5-21-97631821-2522574050-3878054474-1108
Group Name: UAT Group Domain: ABC

Tags (2)
0 Karma

woodcock
Esteemed Legend

Try this:

sourcetype=foo | dualName=case(eventcode==4720, $New account$, eventcode==4728, $member$) | stats dc(sourcetype) AS numSourcetypes by dualName | where numSourcetypes>1
0 Karma

ppablo
Retired

Hi @zuyi21

Since this has duplicate content from your previous post, can you please delete the other one? This one has more details (sample data) for users to help you with. To clarify, you want an alert to trigger if there is a match in the Account Name field under New Account in the event code 4720 with the Account Name under Member in the eventcode 4728? Your previous post had more information on your desired alert trigger.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...