Alerting

How to compare a field found in 2 different event codes?

zuyi21
New Member

Hi, i would like to create alert.
Condition:
match Account name(New account) in eventcode 4720 with Account name(member) in eventcode 4728.

Below is how the log looks like:

Event code 4720:
Subject:
Security ID: S-1-5-21-97631821-2522574050-3878054474-500
Account Name: administrator
Account Domain: ABC
Logon ID: 0x6a7a0
New Account:
Security ID: S-1-5-21-97631821-2522574050-3878054474-1118
Account Name: T1
Account Domain: ABC

Event code 4728:
Subject:
Security ID: S-1-5-21-97631821-2522574050-3878054474-500
Account Name: administrator
Account Domain: ABC
Logon ID: 0x6a7a0
Member:
Security ID: S-1-5-21-97631821-2522574050-3878054474-1118
Account Name: cn=T1,CN=Users,DC=abc,DC=com
Group:
Security ID: S-1-5-21-97631821-2522574050-3878054474-1108
Group Name: UAT Group Domain: ABC

Tags (2)
0 Karma

woodcock
Esteemed Legend

Try this:

sourcetype=foo | dualName=case(eventcode==4720, $New account$, eventcode==4728, $member$) | stats dc(sourcetype) AS numSourcetypes by dualName | where numSourcetypes>1
0 Karma

ppablo
Retired

Hi @zuyi21

Since this has duplicate content from your previous post, can you please delete the other one? This one has more details (sample data) for users to help you with. To clarify, you want an alert to trigger if there is a match in the Account Name field under New Account in the event code 4720 with the Account Name under Member in the eventcode 4728? Your previous post had more information on your desired alert trigger.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...