Alerting

How to compare fields in different Eventcodes?

zuyi21
New Member

Hi,

I would like to compare fields in different Eventcodes.

Example:
In Eventcode 4720, I want to get the info for Creator name and Created account, then find the corresponding 4728 event (showing that the created account in 4720, is in a certain OU, like OU=DEV). If the OU is not equal to DEV, trigger alert.

Thanks

Tags (2)
0 Karma

dolivasoh
Contributor

Joining may help
eventcode=4720 | join account [search eventcode=4728]

Otherwise you can also try

transaction

0 Karma

zuyi21
New Member

Hi, i need help.

Account_Name can be found both in eventcodes 4720 and 4728. How do i display the Account_Name information in both eventcodes?

This is what i have:

sourcetype="WinEventLog:Security" (EventCode=4720 AND Account_Name="administrator") OR (EventCode=4728 AND Account_Name="administrator") 
| eval AccountCreator=mvindex(Account_Name,0) 
| eval AccountCreated=mvindex(Account_Name,1) 
| rename Group_Name as "Modified Group" 
| table _time, host, AccountCreator, AccountCreated, Modifier, "Modified Group", user

Thx.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...