<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Excluding Users from Service Account Values: A Generic Approach? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646655#M223822</link>
    <description>&lt;P&gt;Update the lookup file as new service accounts are added or removed.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jun 2023 13:20:32 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-06-12T13:20:32Z</dc:date>
    <item>
      <title>How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646299#M223710</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm attempting to create a method to exclude users from service account values without excluding a particular service account. Is there a generic approach we can use to identify and exclude both existing and future service accounts?&lt;/SPAN&gt;&lt;BR /&gt;How we could write the search for this use case.&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 16:38:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646299#M223710</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-12T16:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding Users from Service Account Values: A Generic Approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646548#M223795</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Any idea&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2023 17:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646548#M223795</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-11T17:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding Users from Service Account Values: A Generic Approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646553#M223800</link>
      <description>&lt;P&gt;Just use a lookup which lists all accounts to exclude.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2023 19:23:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646553#M223800</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-06-11T19:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding Users from Service Account Values: A Generic Approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646556#M223801</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What if we get the future service accounts?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 02:55:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646556#M223801</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-12T02:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding Users from Service Account Values: A Generic Approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646655#M223822</link>
      <description>&lt;P&gt;Update the lookup file as new service accounts are added or removed.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 13:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646655#M223822</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-06-12T13:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646678#M223831</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;What I need here is like in the event there is a&amp;nbsp;OU=Service IDs ,OU=users,OU=computers exclude all the src_user from the&amp;nbsp;OU=Service IDs only.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 15:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646678#M223831</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-12T15:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646699#M223841</link>
      <description>&lt;P&gt;It would help to have a more defined set of requirements as well sample input and output, but perhaps this will help.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;&amp;lt;your search&amp;gt;&amp;gt;
| where NOT (OU="Service IDs" AND [ | inputlookup mylookup.csv | fields src_user | rename src_user as sAMAccountName | format ]&lt;/LI-CODE&gt;&lt;P&gt;Adjust the &lt;FONT face="courier new,courier"&gt;fields&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;rename&lt;/FONT&gt; commands as necessary to match your fields.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 16:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646699#M223841</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-06-12T16:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646702#M223842</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Why we need lookup&amp;nbsp; table over here . I don't think we need it .Just I want to exclude all the service accounts from the&amp;nbsp;&lt;SPAN&gt;OU="Service IDs" from an event.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 17:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646702#M223842</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-12T17:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646719#M223846</link>
      <description>&lt;P&gt;You don't *need* a lookup.&amp;nbsp; You can put an exclude list directly in the SPL, but that may end up being more difficult to maintain.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 18:53:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646719#M223846</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-06-12T18:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646791#M223864</link>
      <description>&lt;P&gt;...&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2023 07:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646791#M223864</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-17T07:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646899#M223897</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions on this usecase&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 03:28:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646899#M223897</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-14T03:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646989#M223943</link>
      <description>&lt;P&gt;Apart from the redundant "4738" in the macro, this code looks like it should work.&amp;nbsp; How is it failing you?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 14:46:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646989#M223943</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-06-14T14:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646993#M223945</link>
      <description>&lt;P&gt;...&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2023 07:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/646993#M223945</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-17T07:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/647016#M223956</link>
      <description>&lt;P&gt;Debug the query by running the commands before the first | in a new query.&amp;nbsp; Verify the desired fields are present.&amp;nbsp; Add the commands up to the next | and verify the fields are still there.&amp;nbsp; Repeat the process until the fields disappear and you'll have found the source.&amp;nbsp; Post the details if you need help determining the cause.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 17:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/647016#M223956</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-06-14T17:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/647203#M224020</link>
      <description>&lt;P&gt;Here OU is multi value field.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 18:17:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/647203#M224020</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-15T18:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude users from service account values: a generic approach?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/647387#M224064</link>
      <description>&lt;P&gt;Hi , How we can xclude service account from this event.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;Event xmlns='&lt;/SPAN&gt;&lt;A href="http://schemas.microsoft.com/win/2004/08/events/event" target="_blank" rel="noopener nofollow noreferrer"&gt;http://schemas.microsoft.com/win/2004/08/events/event&lt;/A&gt;&lt;SPAN&gt;'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Security-Auditing' Guid='{549549625-5488-43494-AHGBA-3E353B0328CEDQS0D}'/&amp;gt;&amp;lt;EventID&amp;gt;4738&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;0&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;0&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;13824&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;0x8020000000000000&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2023-06-16T16:08:38.166868000Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;668676978&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation/&amp;gt;&amp;lt;Execution ProcessID='656' ThreadID='6132'/&amp;gt;&amp;lt;Channel&amp;gt;Security&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;swrfkeou09.am.win.cisco.com&amp;lt;/Computer&amp;gt;&amp;lt;Security/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='Dummy'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserName'&amp;gt;BP_william_son&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetDomainName'&amp;gt;AM&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetSid'&amp;gt;AM\BP_william_son&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectUserSid'&amp;gt;EC\EC_OktaGMSER$&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectUserName'&amp;gt;EC_OktaGMSER$&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectDomainName'&amp;gt;EC&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectLogonId'&amp;gt;0x7e3yd92a4&amp;lt;/Data&amp;gt;&amp;lt;Data Name='PrivilegeList'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SamAccountName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='DisplayName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='UserPrincipalName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='HomeDirectory'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='HomePath'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ScriptPath'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProfilePath'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='UserWorkstations'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='PasswordLastSet'&amp;gt;%%1794&amp;lt;/Data&amp;gt;&amp;lt;Data Name='AccountExpires'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='PrimaryGroupId'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='AllowedToDelegateTo'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='OldUacValue'&amp;gt;0x15&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewUacValue'&amp;gt;0x10&amp;lt;/Data&amp;gt;&amp;lt;Data Name='UserAccountControl'&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;%%2048&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;%%2050&amp;lt;/Data&amp;gt;&amp;lt;Data Name='UserParameters'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SidHistory'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='LogonHours'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;/EventData&amp;gt;&amp;lt;/Event&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2023 07:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-users-from-service-account-values-a-generic/m-p/647387#M224064</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-06-17T07:05:36Z</dc:date>
    </item>
  </channel>
</rss>

