Splunk Search

domain accounts search csv

japonter
Explorer

Hi,

i have been looking but cant seem to make much sense of it all. im new to splunk.

im trying to create a search and alert from a csv file, the csv fiel contains Domain Admin account and i wanted to creat a search for a numbers of eventid on those domain admin accounts.

index=win sourcetype=wineventlog EventCode=*the events im looking for* | inputlookup file.csv

 

but cant seem to make it work.

 

any help would be great

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Do the field names from your search match the field names in your csv - you should have one that matches to be able to lookup in the csv

0 Karma

japonter
Explorer

the usernames in the csv are name from a AD group called domain admin, if i search for them one by one i find there with the events id, but theres around 70 names and i want to use the csv file to make it easier to search for events with specific eventid with those names.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share some events with the fields you want to match on and the same from the lookup file?

0 Karma

japonter
Explorer

this is one of the events i want to search.

the csv file are just domain admin user names. one column one row of just names.

NOTE: I come from using QRadar for over 5 years, to using splunk for the first time, and i am finding it difficult to transition from one platform to another.

07/06/2021 10:11:23 AM

LogName=Security EventCode=4724

EventType=0 ComputerName=Localhost.local SourceName=Microsoft Windows security auditing. Type=Information RecordNumber=13407054485 Keywords=Audit Success TaskCategory=User Account Management OpCode=Info Message=An attempt was made to reset an account's password.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...