<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to generate a search that will display successful login attempts by members of Domain Admin group? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302570#M91062</link>
    <description>&lt;P&gt;Thanks for this. I've looked through it and it will get me the info I want based on the current Domain Admins group. I am hoping there's a way to update the information from Domain Admins each time I run the query.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2017 17:45:35 GMT</pubDate>
    <dc:creator>scottwhittier</dc:creator>
    <dc:date>2017-02-17T17:45:35Z</dc:date>
    <item>
      <title>How to generate a search that will display successful login attempts by members of Domain Admin group?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302567#M91059</link>
      <description>&lt;P&gt;Pretty new to all this.&lt;/P&gt;

&lt;P&gt;I've got a Splunk 6.5.1 environment gathering data from Windows servers/desktops and Active Directory (AD). Need to create a search that will show me all login attempts and successes by members of the Domain Admins group. I can search data about the logins and I can get group membership via SA-LDAPSearch. How do I make the info about the Domain Admin group members available to the logins search?&lt;/P&gt;

&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 22:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302567#M91059</guid>
      <dc:creator>scottwhittier</dc:creator>
      <dc:date>2017-02-16T22:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate a search that will display successful login attempts by members of Domain Admin group?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302568#M91060</link>
      <description>&lt;P&gt;This may help:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/499526/how-to-search-for-logonlogoff-activity-of-domain-a.html"&gt;https://answers.splunk.com/answers/499526/how-to-search-for-logonlogoff-activity-of-domain-a.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 22:13:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302568#M91060</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-02-16T22:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate a search that will display successful login attempts by members of Domain Admin group?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302569#M91061</link>
      <description>&lt;P&gt;Hi  scottwhittier,&lt;BR /&gt;
to search login,logout and logfail events you have to insert in your search (eventually using a lookup) the following EventIds:&lt;BR /&gt;
528, 529, 530, 531, 532, 533, 534, 535, 536, 537, 538, 539, 540, 4624, 4625, 4634, 4647, 4648, 4672, 4675, 4771, 17055, 18450, 18451, 18452, 18453, 18454, 18455, 18456, 18457, 18458, 18459, 18460, 18461, 24001, 24002, 24003 (the last ones are for Exchange and SQL Server).&lt;BR /&gt;
Beware to duplicated Login Events: each access generates many login events, so you have to filter them using dedup or transaction commands.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 08:22:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302569#M91061</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-02-17T08:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate a search that will display successful login attempts by members of Domain Admin group?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302570#M91062</link>
      <description>&lt;P&gt;Thanks for this. I've looked through it and it will get me the info I want based on the current Domain Admins group. I am hoping there's a way to update the information from Domain Admins each time I run the query.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 17:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-a-search-that-will-display-successful-login/m-p/302570#M91062</guid>
      <dc:creator>scottwhittier</dc:creator>
      <dc:date>2017-02-17T17:45:35Z</dc:date>
    </item>
  </channel>
</rss>

