<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can you help us find web GUI log in attempts from index=_audit? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442039#M3704</link>
    <description>&lt;P&gt;i hope the &lt;CODE&gt;info=succeeded&lt;/CODE&gt; is what you are looking for:&lt;BR /&gt;
Audit:[timestamp=12-20-2018 12:15:38.921, user=user123, action=login attempt, &lt;CODE&gt;info=succeeded&lt;/CODE&gt;, src=12.34.56.78][n/a]&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index="_audit" action=*login*&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;my question on this same topic:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/686177/is-there-a-splunk-account-lockout-for-users-if-you.html"&gt;https://answers.splunk.com/answers/686177/is-there-a-splunk-account-lockout-for-users-if-you.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;As you are a new user to Splunk Answers, you can upvote the answers/comments, &lt;BR /&gt;
if this answer resolved your query, you can select this answer and "accept" it as the answer, so that this question will be moved to answered queue. Happy Splunking!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Dec 2018 08:55:52 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2018-12-20T08:55:52Z</dc:date>
    <item>
      <title>Can you help us find web GUI log in attempts from index=_audit?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442038#M3703</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We're looking for web GUI log in attempts from index=_audit.  Note that for event like following:&lt;/P&gt;

&lt;P&gt;Audit:&lt;CODE&gt;[timestamp=12-20-2018 12:15:38.921, user=user123, action=login attempt, info=succeeded, src=12.34.56.78][n/a]&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;the "action" field is set to "success" instead of "login attempt".  &lt;/P&gt;

&lt;P&gt;Was it set somewhere?  Sorry for the newbie question.&lt;/P&gt;

&lt;P&gt;Thanks a lot.&lt;BR /&gt;
Regards&lt;/P&gt;

&lt;P&gt;EDIT: removed the ip address&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 08:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442038#M3703</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2018-12-20T08:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help us find web GUI log in attempts from index=_audit?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442039#M3704</link>
      <description>&lt;P&gt;i hope the &lt;CODE&gt;info=succeeded&lt;/CODE&gt; is what you are looking for:&lt;BR /&gt;
Audit:[timestamp=12-20-2018 12:15:38.921, user=user123, action=login attempt, &lt;CODE&gt;info=succeeded&lt;/CODE&gt;, src=12.34.56.78][n/a]&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index="_audit" action=*login*&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;my question on this same topic:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/686177/is-there-a-splunk-account-lockout-for-users-if-you.html"&gt;https://answers.splunk.com/answers/686177/is-there-a-splunk-account-lockout-for-users-if-you.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;As you are a new user to Splunk Answers, you can upvote the answers/comments, &lt;BR /&gt;
if this answer resolved your query, you can select this answer and "accept" it as the answer, so that this question will be moved to answered queue. Happy Splunking!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 08:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442039#M3704</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-12-20T08:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help us find web GUI log in attempts from index=_audit?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442040#M3705</link>
      <description>&lt;P&gt;Hi, thanks for your help.&lt;BR /&gt;
I'm just interest to know which configuration makes Splunk changed value of "action" into something different to that stated in the events...  &lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 10:23:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442040#M3705</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2018-12-20T10:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help us find web GUI log in attempts from index=_audit?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442041#M3706</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;could be that someone created a field extraction for audittrail to change the value to "success", since its not the default value.&lt;/P&gt;

&lt;P&gt;You should check that, for example in "All configurations" or you could &lt;CODE&gt;grep&lt;/CODE&gt; on the UI in directory &lt;CODE&gt;$SPLUNK_HOME/etc/users&lt;/CODE&gt; for the word &lt;CODE&gt;action&lt;/CODE&gt; command: &lt;CODE&gt;grep -R action&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 10:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442041#M3706</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-12-20T10:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help us find web GUI log in attempts from index=_audit?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442042#M3707</link>
      <description>&lt;P&gt;&lt;EM&gt;I'm just interest to know which configuration makes Splunk changed value of "action" into something different to that stated in the events...&lt;/EM&gt;&lt;BR /&gt;
i think there are no configurations. It is just the audit log format Splunk developers selected. &lt;/P&gt;

&lt;P&gt;there are only 2 choices:&lt;BR /&gt;
action=login attempt, info=succeeded&lt;BR /&gt;
action=login attempt, info=failed&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 12:41:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442042#M3707</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-12-20T12:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help us find web GUI log in attempts from index=_audit?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442043#M3708</link>
      <description>&lt;P&gt;Thanks and agree.  But when expanding the event fields on web interfrace, we can see that the "action" attribute is set to "success", not "login attempt".&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 17:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442043#M3708</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2018-12-20T17:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help us find web GUI log in attempts from index=_audit?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442044#M3709</link>
      <description>&lt;P&gt;Thanks.  Found that it's done by a transform in the CIM add-on $SPLUNKE_HOME/etc/apps/Splunk_SA_CIM/default/props.conf.&lt;/P&gt;

&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-us-find-web-GUI-log-in-attempts-from-index-audit/m-p/442044#M3709</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2020-09-29T22:26:55Z</dc:date>
    </item>
  </channel>
</rss>

