<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to detect default accounts by Splunk? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364496#M3615</link>
    <description>&lt;P&gt;That lookup have only 30+ default usernames and we don't know topicality of there names.&lt;BR /&gt;
So, any another solutions? &lt;/P&gt;</description>
    <pubDate>Tue, 20 Mar 2018 22:25:01 GMT</pubDate>
    <dc:creator>test_qweqwe</dc:creator>
    <dc:date>2018-03-20T22:25:01Z</dc:date>
    <item>
      <title>How to detect default accounts by Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364494#M3613</link>
      <description>&lt;P&gt;Hi.&lt;BR /&gt;
I see dashboard in ES   4.1.1 aka "Default Account Activity", but he shows activity of all accounts.&lt;/P&gt;

&lt;P&gt;How to detect Default Account? Any solutions?&lt;BR /&gt;
Maybe someone can share list of all default accounts? (I'm tried to google, but got unsatisfactory results).&lt;/P&gt;

&lt;P&gt;By "Default Account" i mean:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Discovers use of default accounts (such as admin, administrator, etc.). Default accounts have default passwords and are therefore commonly targeted by attackers using brute force attack tools."
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 19 Mar 2018 21:40:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364494#M3613</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-03-19T21:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect default accounts by Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364495#M3614</link>
      <description>&lt;P&gt;Hey&lt;/P&gt;

&lt;P&gt;Are you looking for the Administrative lookup of ES?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/en-US/app/SplunkEnterpriseSecuritySuite/ess_lookups_edit?namespace=SA-IdentityManagement&amp;amp;transform=administrative_identity_lookup
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or is it the case that all your logins are being wrongfully tagged with tag="default"?&lt;/P&gt;

&lt;P&gt;Look at the DataSet definition &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;**Default Authentication**

(`cim_Authentication_indexes`) tag=authentication NOT (action=success user=*$) 

Constraint
tag="default"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 20 Mar 2018 07:46:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364495#M3614</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-03-20T07:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect default accounts by Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364496#M3615</link>
      <description>&lt;P&gt;That lookup have only 30+ default usernames and we don't know topicality of there names.&lt;BR /&gt;
So, any another solutions? &lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 22:25:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364496#M3615</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-03-20T22:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect default accounts by Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364497#M3616</link>
      <description>&lt;P&gt;Or, how to search default accounts by Splunk?&lt;BR /&gt;
Because I see  all users are listed in the results not just default accounts like admins and the like.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 23:13:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364497#M3616</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-03-20T23:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect default accounts by Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364498#M3617</link>
      <description>&lt;P&gt;This behaviour is not related to that Lookup. It is actually related to how your events are arriving to Splunk and how they are tagged in the sourcetypes. &lt;/P&gt;

&lt;P&gt;For instance if you have WinEventLog:Security, SYSTEM account is considered by the Splunk_TA_for_Windows as a default account ant therefore tagged as tag=default, and so it shows up in that correlation search.&lt;/P&gt;

&lt;P&gt;You should try to understand why are your events tagged with tag=default in one of the sourcetypes you are getting wrongful data.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:35:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364498#M3617</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2020-09-29T18:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect default accounts by Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364499#M3618</link>
      <description>&lt;P&gt;In my case I am not getting a single default login&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 03:11:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-detect-default-accounts-by-Splunk/m-p/364499#M3618</guid>
      <dc:creator>dikshaj</dc:creator>
      <dc:date>2020-02-09T03:11:24Z</dc:date>
    </item>
  </channel>
</rss>

