<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Account keeps getting locked out in Security</title>
    <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704872#M18228</link>
    <description>&lt;P&gt;Do you have any other sources of information, e.g. other logs, connection logs, meta-data about the "empty" logs, when the events happen, where were they originally logged. Can you work your way back up the chain to find where the event was generated?&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2024 17:23:37 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-11-20T17:23:37Z</dc:date>
    <item>
      <title>Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704727#M18206</link>
      <description>&lt;P&gt;I have an employee who keeps getting locked out. I wanted to know how to put a script in to find out which device is getting locked out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 15:43:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704727#M18206</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-19T15:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: lock out account</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704730#M18207</link>
      <description>&lt;P&gt;Do you have logs ingested into Splunk?&lt;/P&gt;&lt;P&gt;Can you share some anonymised examples of the events you are trying to detect?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 15:41:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704730#M18207</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-19T15:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704732#M18208</link>
      <description>&lt;P&gt;index=* source="activedirectory" eventtype="ad-files" Event*&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;These are the logs I have. They give me a lot of information. However, it is not the computer name that is getting locked out or if they are off-site.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 12:59:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704732#M18208</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-21T12:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704734#M18209</link>
      <description>&lt;P&gt;Thanks. That was the search not the events. Do you have any evidence in logs that you have ingested into Splunk that the user is getting locked out?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 15:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704734#M18209</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-19T15:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704743#M18210</link>
      <description>&lt;P&gt;That search shows some who are locked out and some people who log in to a device. It shows some of everything. I wish it would determine who is locked out instead of stating no for everything.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 16:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704743#M18210</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-19T16:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704746#M18211</link>
      <description>&lt;P&gt;Please share anonymised examples of your log events.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 16:20:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704746#M18211</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-19T16:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704747#M18212</link>
      <description>&lt;P&gt;_time user desc OU hostName lockout&lt;/P&gt;&lt;P&gt;How is this for an example?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 12:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704747#M18212</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-21T12:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704752#M18213</link>
      <description>&lt;P&gt;From what you have shown so far, if the EventCode is "True", the user is locked out and you set lockout to "Yes", but you haven't shown any events where this is the case. Is this because there are no events like this?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 17:47:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704752#M18213</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-19T17:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704760#M18214</link>
      <description>&lt;P&gt;It does show locked-out users as well as unlocked users. Honestly, I know who is locked out and who is not. I wish it would be stated yes when it is instead of no for everyone. But the real issue I have is. How can I know what computer is locked out or if it is off-site?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 18:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704760#M18214</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-19T18:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704788#M18215</link>
      <description>&lt;P&gt;Splunk can only report what it finds in the logged events or something it "calculates" from the events. So, the question remains, what evidence do you have in your log events that show that the user is locked out or off-site? (To be fair, you haven't told us what "locked out" or "off-site" mean, let alone shown evidence of these states!)&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 23:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704788#M18215</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-19T23:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704817#M18216</link>
      <description>&lt;P&gt;I understand you're not able to help. Thanks for your help anyway.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 13:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704817#M18216</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-20T13:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704822#M18217</link>
      <description>&lt;P&gt;It's very difficult to help with a search when we don't know what is being searched.&amp;nbsp; Something in your indexed data must be showing when an account is locked out.&amp;nbsp; Show us those events and we can help you craft a search for them.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 13:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704822#M18217</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-11-20T13:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704826#M18218</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks so much for trying to help me. I agree with what you stated. Something is wrong. However. I did;&lt;/P&gt;&lt;P&gt;I posted what was in the what was in the search.&lt;/P&gt;&lt;P&gt;Then, I posted what was ingested from the logs. I'm not sure what more information you need from me.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 14:00:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704826#M18218</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-20T14:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704831#M18219</link>
      <description>&lt;PRE&gt;&lt;SPAN&gt;| eval lockout=if(EventCode =True,"Yes","No")&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;Can you share how the field "EventCode" is evaluated.&amp;nbsp; You shared your search and the results from your search.&amp;nbsp; What would be helpful is an anonymized raw event which feeds into your search.&lt;/P&gt;&lt;P&gt;Any event which indicates an account is in lock out status may not show where the authentication attempt came from.&amp;nbsp; This is why knowing the raw event is helpful to outsiders providing feedback.&amp;nbsp; If you are really trying to discover the root of account lock outs then you need a search for failed log in attempts.&amp;nbsp; The 2 data sets might come from different log entries.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 14:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704831#M18219</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-11-20T14:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704833#M18220</link>
      <description>&lt;P&gt;What you posted with respect to the logs was a table of value for fields (presumably derived from your events). What would be more useful is the raw events e.g. the _raw field for the events you are trying to use to determine which device(s) the user(s) is(are) locked out from. If this evidence is not in your raw event data, it is highly unlikely that Splunk can help you find it. Having said that, there may be a sequence or possibly an incomplete sequence of events that indicate that a user failed to connect. For example, you may have evidence in your logs of connections and failed log in attempts on those sessions, or even just connection attempts. We have no idea until you share what information you have.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 14:27:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704833#M18220</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-20T14:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704840#M18221</link>
      <description>&lt;P&gt;Thanks for the information and explaining again what information you wanted. Here is the raw data you requested:&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 12:57:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704840#M18221</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-22T12:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704841#M18222</link>
      <description>&lt;P&gt;Thank for the information&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 15:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704841#M18222</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-20T15:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704845#M18223</link>
      <description>&lt;P class="lia-align-left"&gt;As I looked into the information you asked me for, the eventcode is supposed to lock out event code 4740, and it stated yes for lockout if it locks out. And No, if it is not. But in the raw data. It seems like my lockout question, doesn't exist.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 15:48:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704845#M18223</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-20T15:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704847#M18224</link>
      <description>&lt;P&gt;So you don't have any events for the locked accounts?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 16:38:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704847#M18224</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-20T16:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Account keeps getting locked out</title>
      <link>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704848#M18225</link>
      <description>&lt;P&gt;The Statistics show locked and unlocked accounts, but the raw data does not show the event codes 4740 for yes and no.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 16:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Account-keeps-getting-locked-out/m-p/704848#M18225</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2024-11-20T16:43:12Z</dc:date>
    </item>
  </channel>
</rss>

