Splunk Search

Search to find unauthorized host(s) last login date

cjsweeney1
Explorer

Hi looking for a search to find any unauthorized systems that are sitting on a network and the last login date.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To find unauthorized systems you'll first need a list of the authorized systems, perhaps in a lookup file. Then search to find ALL systems on your network and compare that list to the authorized list. The difference is the unauthorized systems.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cjsweeney1
Explorer

Hey Rich,

You know a search string to find a particular hosts last ip "pull" is... I'm wondering if the last time it had a DHCP timestamp assigned is all I will be able to get.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't know that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cjsweeney1
Explorer

Hmmm.... could work. Could that lookup file be automatically updated? I was hoping enterprise security would have a report like this built-in.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it's possible to automatically update the lookup file.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...