Splunk Search

Bad passwords logged in the DC Netlogon logs:

Bis
Loves-to-Learn Lots

Bad passwords logged in the DC Netlogon logs:

for a specific account name:  index=cim sourcetype=netlogon host=*dc* "0xC000006A" Logon_Account="*<accountname>”  *** need the asterisk since the netlogon log usually puts the domain netbios name in front of the account name,

for a specific account by source:  index=cim sourcetype=netlogon host=*dc* "0xC000006A" Logon_Account="*<accountname>”   *** same query as above because I did not find an easy way to get the bad password source. 

Anyone please help me splunk.JPG

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...