<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Users loging into workstations with local admin or domain admin privs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516574#M145193</link>
    <description>&lt;P&gt;Yes, I do see 4672 from end points.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk.jpg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10545i437DED023027E7D8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Splunk.jpg" alt="Splunk.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2020 18:56:57 GMT</pubDate>
    <dc:creator>ldefoor</dc:creator>
    <dc:date>2020-08-27T18:56:57Z</dc:date>
    <item>
      <title>Users loging into workstations with local admin or domain admin privs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516312#M145080</link>
      <description>&lt;P&gt;First off, I am very new to Splunk and that may be my downfall. Our latest Splunk guru has left and this fell to me rather abruptly, so I apologize in advance.&lt;/P&gt;&lt;P&gt;I have been tasked with generating a report showing users that are logging into the local computers with elevated privileges of their standard daily accounts.&lt;/P&gt;&lt;P&gt;For example, if a user has two logins, username and ADUserName. I need to find out if username is a local admin on their computer and when they have logged in using that account.&lt;/P&gt;&lt;P&gt;I have been trying to figure this out but for the last two weeks haven't actually made any progress.&lt;/P&gt;&lt;P&gt;Hoping someone can point me in the right direction - thank you very much!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 16:15:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516312#M145080</guid>
      <dc:creator>ldefoor</dc:creator>
      <dc:date>2020-08-26T16:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Users loging into workstations with local admin or domain admin privs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516364#M145092</link>
      <description>&lt;P&gt;Are you collecting logs from endpoints to see if &amp;nbsp;user is making login locally instead using his/her domain account.&lt;/P&gt;&lt;P&gt;You need to have event logs from each endpoint to detect if they are login &amp;nbsp;locally using admin rights. 4672 is the event code.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4672" target="_blank"&gt;https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4672&lt;/A&gt;&lt;/P&gt;&lt;P&gt;or you could easily detect employees who are login using local admin account if you have Microsoft defender ATP installed on endpoints.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 19:28:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516364#M145092</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-26T19:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Users loging into workstations with local admin or domain admin privs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516367#M145094</link>
      <description>&lt;P&gt;We are ingesting those logs from all the end points.&lt;/P&gt;&lt;P&gt;I have searched on that and am only finding systems logging in with elevated privs. I know the admins are doing this, they will tell me they are, but looking for a way to see the activity &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 19:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516367#M145094</guid>
      <dc:creator>ldefoor</dc:creator>
      <dc:date>2020-08-26T19:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Users loging into workstations with local admin or domain admin privs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516569#M145190</link>
      <description>&lt;P&gt;Did you see 4672 events collected from endpoints?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 18:45:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516569#M145190</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-27T18:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Users loging into workstations with local admin or domain admin privs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516574#M145193</link>
      <description>&lt;P&gt;Yes, I do see 4672 from end points.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk.jpg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10545i437DED023027E7D8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Splunk.jpg" alt="Splunk.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 18:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516574#M145193</guid>
      <dc:creator>ldefoor</dc:creator>
      <dc:date>2020-08-27T18:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Users loging into workstations with local admin or domain admin privs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516575#M145194</link>
      <description>&lt;P&gt;Can you try accessing endpoint using local admin account and see how events is generated then you can understand event behavior.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 18:58:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Users-loging-into-workstations-with-local-admin-or-domain-admin/m-p/516575#M145194</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-27T18:58:31Z</dc:date>
    </item>
  </channel>
</rss>

