Alerting

How to compare fields in different Eventcodes?

zuyi21
New Member

Hi,

I would like to compare fields in different Eventcodes.

Example:
In Eventcode 4720, I want to get the info for Creator name and Created account, then find the corresponding 4728 event (showing that the created account in 4720, is in a certain OU, like OU=DEV). If the OU is not equal to DEV, trigger alert.

Thanks

Tags (2)
0 Karma

dolivasoh
Contributor

Joining may help
eventcode=4720 | join account [search eventcode=4728]

Otherwise you can also try

transaction

0 Karma

zuyi21
New Member

Hi, i need help.

Account_Name can be found both in eventcodes 4720 and 4728. How do i display the Account_Name information in both eventcodes?

This is what i have:

sourcetype="WinEventLog:Security" (EventCode=4720 AND Account_Name="administrator") OR (EventCode=4728 AND Account_Name="administrator") 
| eval AccountCreator=mvindex(Account_Name,0) 
| eval AccountCreated=mvindex(Account_Name,1) 
| rename Group_Name as "Modified Group" 
| table _time, host, AccountCreator, AccountCreated, Modifier, "Modified Group", user

Thx.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...