<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Password Reset Command for Splunk in Security</title>
    <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446908#M15085</link>
    <description>&lt;P&gt;hi @keldridg2  - The _audit index, as the name suggests contains ALL(well, as much as splunk default audit info goes) audit information irrespective of the number of indexes you have, you log into splunk and not to an individual index.&lt;BR /&gt;
Are we on the same page or is your need something different?&lt;BR /&gt;
See for example how the above query captures password change info of splunk overall and NOT for any specific index.&lt;BR /&gt;
Am I misunderstanding your question?&lt;BR /&gt;
    4/7/19&lt;BR /&gt;
    5:25:39.835 PM&lt;BR /&gt;&lt;BR /&gt;
    Audit:[timestamp=04-07-2019 17:25:39.835, user=admin, action=password change, info=succeeded][n/a]&lt;BR /&gt;
    action =    password change host =  vvvvv source =  audittrail sourcetype = audittrail user =   admin&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2019 17:18:49 GMT</pubDate>
    <dc:creator>Sukisen1981</dc:creator>
    <dc:date>2019-08-14T17:18:49Z</dc:date>
    <item>
      <title>Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446903#M15080</link>
      <description>&lt;P&gt;Can somebody show me a Splunk command on how to find a number of password resets and how I can display the total number of password resets to that user? &lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 16:15:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446903#M15080</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-14T16:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446904#M15081</link>
      <description>&lt;P&gt;something like this - ? index=_audit "action=password change"&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 16:26:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446904#M15081</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-08-14T16:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446905#M15082</link>
      <description>&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 16:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446905#M15082</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-14T16:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446906#M15083</link>
      <description>&lt;P&gt;hi @keldridg2 - Did it work or did you have to do something different?&lt;BR /&gt;
If this worked I will convert the comment into an answer, please accept it after the same.&lt;BR /&gt;
If it did not and you did something else to resolve the issue please share your answer.&lt;BR /&gt;
Both ways will benefit forum members who might face a similar issue in the future&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 16:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446906#M15083</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-08-14T16:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446907#M15084</link>
      <description>&lt;P&gt;I founded that we do have the index=_audit but am wondering if it was index=main then how would I find the password change then.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 16:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446907#M15084</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-14T16:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446908#M15085</link>
      <description>&lt;P&gt;hi @keldridg2  - The _audit index, as the name suggests contains ALL(well, as much as splunk default audit info goes) audit information irrespective of the number of indexes you have, you log into splunk and not to an individual index.&lt;BR /&gt;
Are we on the same page or is your need something different?&lt;BR /&gt;
See for example how the above query captures password change info of splunk overall and NOT for any specific index.&lt;BR /&gt;
Am I misunderstanding your question?&lt;BR /&gt;
    4/7/19&lt;BR /&gt;
    5:25:39.835 PM&lt;BR /&gt;&lt;BR /&gt;
    Audit:[timestamp=04-07-2019 17:25:39.835, user=admin, action=password change, info=succeeded][n/a]&lt;BR /&gt;
    action =    password change host =  vvvvv source =  audittrail sourcetype = audittrail user =   admin&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 17:18:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446908#M15085</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-08-14T17:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446909#M15086</link>
      <description>&lt;P&gt;The answer by @Sukisen1981 is a good one, but only applies to changes users make to their Splunk passwords.  To find other password changes in your environment, you will have to know how those changes are reported to Splunk, if at all.  They could be in a Windows event, a Linux audit record, or some application log.  We'll need more information to help you better.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 17:23:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446909#M15086</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-14T17:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446910#M15087</link>
      <description>&lt;P&gt;No this is what I am looking for. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 17:24:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446910#M15087</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-14T17:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446911#M15088</link>
      <description>&lt;P&gt;index=main host=* source=* sourcetype=* password reset Account_Name=* | top limit=10 Account_Name&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446911#M15088</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2020-09-30T01:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446912#M15089</link>
      <description>&lt;P&gt;This is what I am referring to.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 17:45:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446912#M15089</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-14T17:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446913#M15090</link>
      <description>&lt;P&gt;hi @keldridg2 - As much as I like earning karma points &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; , I can not see how my answer helps for your question.&lt;BR /&gt;
Your sourcetype is custom and it looks like neither my suggestion nor @richgalloway 's suggestion is related to your requirement.&lt;BR /&gt;
Please un-accept my answer, as I feel it has not contributed significantly to your issue.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 18:13:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446913#M15090</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-08-14T18:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446914#M15091</link>
      <description>&lt;P&gt;Sorry you do not feel like you contributed but your answer will help me with future uses as I been trying to research how to do a reset command but could only find ways how to reset Splunk password. It was difficult with wording what my idea is with index=main but do feel like your answer does help me out if a users decides to change their Splunk password.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 19:10:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446914#M15091</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-14T19:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446915#M15092</link>
      <description>&lt;P&gt;no worries &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; thanks for your time, do hope your issue is solved .. have a nice day / night ahead &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 19:14:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446915#M15092</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-08-14T19:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset Command for Splunk</title>
      <link>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446916#M15093</link>
      <description>&lt;P&gt;I will accept your answer and give you the points as I do feel like you help many people probably with this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 19:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Password-Reset-Command-for-Splunk/m-p/446916#M15093</guid>
      <dc:creator>keldridg2</dc:creator>
      <dc:date>2019-08-14T19:19:14Z</dc:date>
    </item>
  </channel>
</rss>

