<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Searching events after log in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Searching-events-after-log/m-p/525778#M88740</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to create the alert that:&lt;/P&gt;&lt;P&gt;someone login to system (event login = successful login) and I just want to check if in 5 min from this event, was any user or group was created by user (which is not member of admin group).&lt;/P&gt;&lt;P&gt;or another version:&lt;/P&gt;&lt;P&gt;If X notification was triggered +&amp;nbsp; notification about new user or new group was triggered (created not by admin)- but 1h before and 1h after notification X (timestamp), then: generate alert&lt;/P&gt;&lt;P&gt;Could you please provide some tips for this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;</description>
    <pubDate>Wed, 21 Oct 2020 13:37:46 GMT</pubDate>
    <dc:creator>JacobWrdz</dc:creator>
    <dc:date>2020-10-21T13:37:46Z</dc:date>
    <item>
      <title>Searching events after log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Searching-events-after-log/m-p/525778#M88740</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to create the alert that:&lt;/P&gt;&lt;P&gt;someone login to system (event login = successful login) and I just want to check if in 5 min from this event, was any user or group was created by user (which is not member of admin group).&lt;/P&gt;&lt;P&gt;or another version:&lt;/P&gt;&lt;P&gt;If X notification was triggered +&amp;nbsp; notification about new user or new group was triggered (created not by admin)- but 1h before and 1h after notification X (timestamp), then: generate alert&lt;/P&gt;&lt;P&gt;Could you please provide some tips for this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 13:37:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Searching-events-after-log/m-p/525778#M88740</guid>
      <dc:creator>JacobWrdz</dc:creator>
      <dc:date>2020-10-21T13:37:46Z</dc:date>
    </item>
  </channel>
</rss>

