<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Account Lockout in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/651548#M16877</link>
    <description>&lt;P&gt;Use a field name that uniquely identifies the specific alert you wish to throttle.&amp;nbsp; In this case, that field would be Account_Name since you don't want repeated alerts for users.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jul 2023 19:15:06 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-07-21T19:15:06Z</dc:date>
    <item>
      <title>Splunk Account Lockout</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/650803#M16845</link>
      <description>&lt;P&gt;I have just configured Splunk and I have alert running for locked account.&lt;/P&gt;&lt;P&gt;It keep generating multiple entries from per lockout account&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I want to generate one message incase of account get locked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=wineventlog source="WinEventLog:Security" sourcetype=WinEventLog action=failure Account_Name="*" user="*" AND "taskcategory=Account Lockout"&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 10:44:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/650803#M16845</guid>
      <dc:creator>OsmanElyas</dc:creator>
      <dc:date>2023-07-17T10:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Account Lockout</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/650870#M16849</link>
      <description>&lt;P&gt;What you want is to throttle the alert.&amp;nbsp; Throttling prevents the alert from firing too often.&amp;nbsp; To turn on throttling, edit the alert and check the box labled "Thottle" then specify how long you want Splunk to wait before firing the alert again.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 16:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/650870#M16849</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-17T16:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Account Lockout</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/650932#M16855</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Thank you for the guide I am still facing small issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;what should be in the filed&amp;nbsp;Suppress results containing field value when I click on throttle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Jul 2023 06:35:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/650932#M16855</guid>
      <dc:creator>OsmanElyas</dc:creator>
      <dc:date>2023-07-18T06:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Account Lockout</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/651548#M16877</link>
      <description>&lt;P&gt;Use a field name that uniquely identifies the specific alert you wish to throttle.&amp;nbsp; In this case, that field would be Account_Name since you don't want repeated alerts for users.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 19:15:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/651548#M16877</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-21T19:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Account Lockout</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/651675#M16892</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Much appreciate your support, I have implemented the report.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 06:43:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/651675#M16892</guid>
      <dc:creator>OsmanElyas</dc:creator>
      <dc:date>2023-07-24T06:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Account Lockout</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/651761#M16900</link>
      <description>&lt;P&gt;If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 12:48:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Account-Lockout/m-p/651761#M16900</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-24T12:48:09Z</dc:date>
    </item>
  </channel>
</rss>

