<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logging Login Data of VM in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688164#M10195</link>
    <description>&lt;P&gt;But if the VM does not log those Data so far it is not possible?&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2024 13:08:50 GMT</pubDate>
    <dc:creator>Jan21</dc:creator>
    <dc:date>2024-05-21T13:08:50Z</dc:date>
    <item>
      <title>Logging Login Data of VM</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688145#M10193</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i wanted to ask if there is a way in Splunk to collect failured Login Data from Users on a Virtual Machine that is hosted with VMware, so that i can see if a user tried to login like 5 times and failed the Login on VM 5 times?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would be nice to use it for finding out if there is some Kind of Brute Force Attack or something else going on.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 10:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688145#M10193</guid>
      <dc:creator>Jan21</dc:creator>
      <dc:date>2024-05-21T10:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Logging Login Data of VM</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688153#M10194</link>
      <description>&lt;P&gt;Yes, it is possible.&amp;nbsp; If the VM or identity provider logs failed logins to Splunk then you can search those events for multiple attempts within a given timeframe.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 12:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688153#M10194</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-05-21T12:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Logging Login Data of VM</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688164#M10195</link>
      <description>&lt;P&gt;But if the VM does not log those Data so far it is not possible?&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 13:08:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688164#M10195</guid>
      <dc:creator>Jan21</dc:creator>
      <dc:date>2024-05-21T13:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Logging Login Data of VM</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688166#M10196</link>
      <description>&lt;P&gt;Splunk cannot search what it doesn't have.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 13:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Logging-Login-Data-of-VM/m-p/688166#M10196</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-05-21T13:15:08Z</dc:date>
    </item>
  </channel>
</rss>

