<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ellobrate this event in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591579#M8857</link>
    <description>&lt;P&gt;Grep for this in the savesearches.conf from the Splunk instance in the backend if you can.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;cd /opt/splunk/etc/
grep -rinl "Single User Failed Attempt"&lt;/LI-CODE&gt;&lt;P&gt;See if you can see a file that contains it. (Specifically savedsearches.conf)&lt;BR /&gt;That should give an answer in most cases.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2022 17:09:08 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2022-03-30T17:09:08Z</dc:date>
    <item>
      <title>How do I Ellobrate this event?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591457#M8850</link>
      <description>&lt;P&gt;Hi splunk experts,&lt;/P&gt;
&lt;P&gt;Can anyone elaborate this below event and tell me why this event is getting triggered? the user name in this event has left the organization and we removed his access and transferred the knowledge objects to other person also but we are getting his name in the below event. and please help me how to avoid this type type of alerts also.&lt;/P&gt;
&lt;P&gt;127.0.0.1 - **User name*** [30/Mar/2022:09:29:54.891 +0000] "POST /servicesNS/nobody/search/saved/searches/Single%20User%20Failed%20Attempt/notify?trigger.condition_state=1 HTTP/1.1" 200 1933 "-" "Splunk/8.1.0 (Linux 4.15.0-1023-azure; arch=x86_64)" - 2ms&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this event is getting displayed when we search by using the query: index=_internal sourcetype= splunkd_access user=*.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:27:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591457#M8850</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-30T17:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591462#M8851</link>
      <description>&lt;P&gt;It looks like something is running on local host. How often does it happen? Could it be a cronjob or something like that?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 10:02:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591462#M8851</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-30T10:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591464#M8852</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This event is generating everyday and its not only with one user, its with multiple users who left the organization. The cronjob are like knowledge objects, but all the knowledge objects created by the user is assigned to the new user. so can you please suggest me how can we check any new cronjobs that are available. and how can we check in local host as well????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance..&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 10:12:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591464#M8852</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-30T10:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591466#M8853</link>
      <description>&lt;P&gt;Every day? At the same time every day or at random times?&lt;/P&gt;&lt;P&gt;What do you mean by "&lt;SPAN&gt;cronjob are like knowledge objects"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you have shell access to your splunk hosts?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What other processes are running on your splunk hosts?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What other users are logged on to your splunk hosts?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 10:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591466#M8853</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-30T10:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591472#M8854</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please find the answers according to your queries... and please revert me incase if any of the info is required.&lt;/P&gt;&lt;P&gt;every day? At the same time every day or at random times? -- these events are triggering for every minute&lt;/P&gt;&lt;P&gt;What do you mean by "cronjob are like knowledge objects"? -- cronjob in splunk is meant to be knowledge objects such as dashboards, alerts, reports which are scheduled to run on specific time. (As of my knowledge) please share what do you mean by cronjob in your opinion.&lt;/P&gt;&lt;P&gt;Do you have shell access to your splunk hosts? -- yes i do have access to shell in splunk host&lt;/P&gt;&lt;P&gt;What other processes are running on your splunk hosts? --&amp;nbsp; there were so many processes are running in splunk host, as i checked by using command &lt;U&gt;&lt;STRONG&gt;ps aux. &lt;/STRONG&gt;&lt;/U&gt;Is there any specific processes that i have to look at?&lt;/P&gt;&lt;P&gt;What other users are logged on to your splunk hosts? -- Is this about the user in the splunk or the users that can access the splunk host.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 11:05:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591472#M8854</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-30T11:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591477#M8855</link>
      <description>&lt;P&gt;How is the saved search "&lt;SPAN&gt;Single User Failed Attempt" set up? Who owns it? Which user does it run as?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 11:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591477#M8855</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-30T11:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591484#M8856</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the "Single User Failed Attempt" is setup as an alert type. it was previously owned by the member that left the organisation (mentioned in the above thread ***user name***), after he left i have reassigned the alert to myself. this alert does not run by any user as it was kept as real time alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance....&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 11:41:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591484#M8856</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-30T11:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591579#M8857</link>
      <description>&lt;P&gt;Grep for this in the savesearches.conf from the Splunk instance in the backend if you can.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;cd /opt/splunk/etc/
grep -rinl "Single User Failed Attempt"&lt;/LI-CODE&gt;&lt;P&gt;See if you can see a file that contains it. (Specifically savedsearches.conf)&lt;BR /&gt;That should give an answer in most cases.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:09:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591579#M8857</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-30T17:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591591#M8858</link>
      <description>&lt;P&gt;How did you reassign the alert?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:23:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591591#M8858</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-30T17:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591600#M8859</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;i clicked on the All Configurations in the settings option to get all Knowledge objects&amp;nbsp; and filtered them for the previous owner. Then i reassigned all the alerts and reports from him to the new user.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 04:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591600#M8859</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-31T04:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591661#M8860</link>
      <description>&lt;P class="lia-align-left"&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;thank you for your response.&lt;/P&gt;&lt;P class="lia-align-left"&gt;in the splunk instance i have go till opt directory, but in opt directory i cant find splunk. it only contains the backup scripts. is there any other way that i can look into.....&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 04:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591661#M8860</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-31T04:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591672#M8861</link>
      <description>&lt;P&gt;By &lt;STRONG&gt;/opt/splunk&lt;/STRONG&gt; I meant your Splunk installation directory. This is generally the case but it seems in your case Splunk is installed in a different location.&lt;/P&gt;&lt;P&gt;* I hope you are in the backend of search head.&lt;/P&gt;&lt;P&gt;* You can find the Splunk installation directory by running the command, &lt;STRONG&gt;find / -name "splunk" -type d&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 05:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591672#M8861</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-31T05:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591679#M8862</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have checked the path and i do find the savedsearches.conf in mutiple directories.&lt;/P&gt;&lt;P&gt;1. /data/splunk/etc/system/default/savedsearches.conf&lt;/P&gt;&lt;P&gt;2. /data/splunk/etc/apps/search/default/savedsearches.conf&lt;/P&gt;&lt;P&gt;3. /data/splunk/etc/apps/splunk_monitoring_console/default/savedsearches.conf&lt;/P&gt;&lt;P&gt;4. /data/splunk/etc/apps/Splunk_TA_paloalto/default/savedsearches.conf (there are so many savedsearches in different directories with different app name.)&lt;/P&gt;&lt;P&gt;Please suggest me in which do i have to look the savedsearches.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance...&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 05:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591679#M8862</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-31T05:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591682#M8863</link>
      <description>&lt;P&gt;Try this now:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;cd /data/splunk/etc/
grep -rinl "Single User Failed Attempt"&lt;/LI-CODE&gt;&lt;P&gt;And see where this alert is still present.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 05:49:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591682#M8863</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-31T05:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591686#M8864</link>
      <description>&lt;P&gt;Dear &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your previous reply i have go through it but there are so many files that came up with permission denied. And i haven't found any single user attempt failed in it.&lt;/P&gt;&lt;P&gt;please revert me in there is any other way..&lt;/P&gt;&lt;P&gt;thanks in advance....&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 06:01:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591686#M8864</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-31T06:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591689#M8865</link>
      <description>&lt;P&gt;Seems like a file permission issue you are facing.&lt;/P&gt;&lt;P&gt;Run the commands with the root user.&amp;nbsp; Or prepend the commands with &lt;STRONG&gt;sudo&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 06:05:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591689#M8865</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-31T06:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591697#M8866</link>
      <description>&lt;P&gt;Thank you very much &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have found the savedsearches.conf but i can,t access the file due to privilege issues. i will contact my server team and transfer the duplicate file to my pc. and can you please suggest me what i have to search in the conf file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 06:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591697#M8866</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-31T06:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591698#M8867</link>
      <description>&lt;P&gt;Look for the stanza name (below line) in the file. That should give you the answer you are looking for why that username is still showing in the logs.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Single User Failed Attempt]&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 31 Mar 2022 06:30:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591698#M8867</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-31T06:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591727#M8870</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have checked the savedsearches.conf for single user attempt and it is as below and everything is normal in it and i didn't find any abnormality in it. please find the screenshot in it and please tell me if you find any abnormality.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mohanveera1_0-1648721206703.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18873iC385C8446C270D34/image-size/large?v=v2&amp;amp;px=999" role="button" title="Mohanveera1_0-1648721206703.png" alt="Mohanveera1_0-1648721206703.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.....&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 10:09:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591727#M8870</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-31T10:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Ellobrate this event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591740#M8871</link>
      <description>Which location did you find this file?&lt;BR /&gt;&lt;BR /&gt;Other than that I don't see any issues, unless Splunk is behaving something differently.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 31 Mar 2022 11:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-Ellobrate-this-event/m-p/591740#M8871</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-31T11:33:37Z</dc:date>
    </item>
  </channel>
</rss>

