<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to generate a search for the creation of admin accounts? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347438#M102897</link>
    <description>&lt;P&gt;for windows look for events 4720 account was created and 4732 (or related) account was added to a global security group&lt;BR /&gt;
read here and then move to related events (from the link)&lt;BR /&gt;
&lt;A href="https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720"&gt;https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720&lt;/A&gt;&lt;BR /&gt;
linux has less verbose logging than windows but i can think of some ways to monitor that. &lt;BR /&gt;
most of the time each user will have its own home directory and therefore if you see a new source it means a new user.&lt;BR /&gt;
also there are ways to monitor the suduers list on linux&lt;BR /&gt;
hope it helps a little&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2017 16:14:10 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2017-06-15T16:14:10Z</dc:date>
    <item>
      <title>How to generate a search for the creation of admin accounts?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347436#M102895</link>
      <description>&lt;P&gt;need a search for creation of admin accounts.   For both Windows and Linux.  Domain-level accounts.  Thanks &lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 15:28:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347436#M102895</guid>
      <dc:creator>MastaMia</dc:creator>
      <dc:date>2017-06-15T15:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate a search for the creation of admin accounts?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347437#M102896</link>
      <description>&lt;P&gt;@MastaMia - In general, your question has a greater chance of being answered by experts in the Answers community when when you provide as much information and context as possible.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 15:43:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347437#M102896</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-06-15T15:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate a search for the creation of admin accounts?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347438#M102897</link>
      <description>&lt;P&gt;for windows look for events 4720 account was created and 4732 (or related) account was added to a global security group&lt;BR /&gt;
read here and then move to related events (from the link)&lt;BR /&gt;
&lt;A href="https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720"&gt;https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720&lt;/A&gt;&lt;BR /&gt;
linux has less verbose logging than windows but i can think of some ways to monitor that. &lt;BR /&gt;
most of the time each user will have its own home directory and therefore if you see a new source it means a new user.&lt;BR /&gt;
also there are ways to monitor the suduers list on linux&lt;BR /&gt;
hope it helps a little&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 16:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347438#M102897</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-06-15T16:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate a search for the creation of admin accounts?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347439#M102898</link>
      <description>&lt;P&gt;interesting idea.  How would you find the home directories?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 19:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-for-the-creation-of-admin-accounts/m-p/347439#M102898</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-06-15T19:28:30Z</dc:date>
    </item>
  </channel>
</rss>

