Alerting

How to compare fields in different Eventcodes?

zuyi21
New Member

Hi,

I would like to compare fields in different Eventcodes.

Example:
In Eventcode 4720, I want to get the info for Creator name and Created account, then find the corresponding 4728 event (showing that the created account in 4720, is in a certain OU, like OU=DEV). If the OU is not equal to DEV, trigger alert.

Thanks

Tags (2)
0 Karma

dolivasoh
Contributor

Joining may help
eventcode=4720 | join account [search eventcode=4728]

Otherwise you can also try

transaction

0 Karma

zuyi21
New Member

Hi, i need help.

Account_Name can be found both in eventcodes 4720 and 4728. How do i display the Account_Name information in both eventcodes?

This is what i have:

sourcetype="WinEventLog:Security" (EventCode=4720 AND Account_Name="administrator") OR (EventCode=4728 AND Account_Name="administrator") 
| eval AccountCreator=mvindex(Account_Name,0) 
| eval AccountCreated=mvindex(Account_Name,1) 
| rename Group_Name as "Modified Group" 
| table _time, host, AccountCreator, AccountCreated, Modifier, "Modified Group", user

Thx.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...