<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed Logins in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145625#M185180</link>
    <description>&lt;P&gt;Thanks a lot for reply.&lt;BR /&gt;
Q: are you search the correct index? &lt;BR /&gt;
A: Yes&lt;BR /&gt;
Q: do you have permission to search the correct index? &lt;BR /&gt;
A: I am the administrator of our Splunk. &lt;BR /&gt;
Q: beside the time range you've selected, is the time zone for this event maybe in an other time range? &lt;BR /&gt;
A: I have selected different time ranges in this.&lt;BR /&gt;
Q: can you find anything if you search for the user id in question? &lt;BR /&gt;
A: I did not understand this.&lt;BR /&gt;
Q: is the log/eventlog being picked up by Splunk so you have the events indexed after all? &lt;BR /&gt;
A: Yes&lt;BR /&gt;
Q: is the UF, which should pick up the upper mentioned events, running? &lt;BR /&gt;
A: Yes&lt;/P&gt;</description>
    <pubDate>Wed, 30 Apr 2014 05:08:41 GMT</pubDate>
    <dc:creator>udayk1</dc:creator>
    <dc:date>2014-04-30T05:08:41Z</dc:date>
    <item>
      <title>Failed Logins</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145623#M185178</link>
      <description>&lt;P&gt;I am observing the failed logins of a user and it is getting locked quite frequently morning between 01:30 AM to 02:30 AM, could not find the reason and if we trying to retrieve the logs from splunk regarding the failed logins we are not able to get the relevant logs, this is the query which I am executing please let me know if any other query we can put. I am just searching &lt;EM&gt;failed&lt;/EM&gt; for last 24hours. But no response. &lt;/P&gt;

&lt;P&gt;We are receiving the failed logins of all the other user IDs.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 07:07:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145623#M185178</guid>
      <dc:creator>udayk1</dc:creator>
      <dc:date>2014-04-29T07:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Failed Logins</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145624#M185179</link>
      <description>&lt;P&gt;Hi udayk1,&lt;/P&gt;

&lt;P&gt;well, there could be many reasons for events not showing up...here are some basic checks for you:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;are you search the correct index? &lt;/LI&gt;
&lt;LI&gt;do you have permission to search the correct index?&lt;/LI&gt;
&lt;LI&gt;beside the time range you've selected, is the time zone for this event maybe in an other time range?&lt;/LI&gt;
&lt;LI&gt;can you find anything if you search for the user id in question?&lt;/LI&gt;
&lt;LI&gt;is the log/eventlog being picked up by Splunk so you have the events indexed after all?&lt;/LI&gt;
&lt;LI&gt;is the UF, which should pick up the upper mentioned events, running?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 07:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145624#M185179</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-04-29T07:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Failed Logins</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145625#M185180</link>
      <description>&lt;P&gt;Thanks a lot for reply.&lt;BR /&gt;
Q: are you search the correct index? &lt;BR /&gt;
A: Yes&lt;BR /&gt;
Q: do you have permission to search the correct index? &lt;BR /&gt;
A: I am the administrator of our Splunk. &lt;BR /&gt;
Q: beside the time range you've selected, is the time zone for this event maybe in an other time range? &lt;BR /&gt;
A: I have selected different time ranges in this.&lt;BR /&gt;
Q: can you find anything if you search for the user id in question? &lt;BR /&gt;
A: I did not understand this.&lt;BR /&gt;
Q: is the log/eventlog being picked up by Splunk so you have the events indexed after all? &lt;BR /&gt;
A: Yes&lt;BR /&gt;
Q: is the UF, which should pick up the upper mentioned events, running? &lt;BR /&gt;
A: Yes&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 05:08:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145625#M185180</guid>
      <dc:creator>udayk1</dc:creator>
      <dc:date>2014-04-30T05:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: Failed Logins</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145626#M185181</link>
      <description>&lt;P&gt;so, you get some results for your search but not if you search for &lt;CODE&gt;failed&lt;/CODE&gt; is that correct? Have you checked if you get the &lt;CODE&gt;failed&lt;/CODE&gt;message in the source which is read by Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 05:14:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Failed-Logins/m-p/145626#M185181</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-04-30T05:14:28Z</dc:date>
    </item>
  </channel>
</rss>

