Alerting

How to configure NPS to forward login error logs to Splunk server and set up an alert when accounts are locked?

bucfan609
New Member

Good morning...

I am very new to Splunk (I am sure that this is how a lot of people begin their posts....but anywho) and am trying to get info from an NPS server to a newly created splunk server. I need to troubleshoot some wireless issues with an Aerohive wireless infrastructure. I have the APs sending syslog data to Splunk and although it does in fact send info there, I need stuff specifically with login errors and possibly the ability to create alerts when accounts are locked.

Thanks in advance for the help.

0 Karma

patmalone_jdsuc
New Member

I am new to Splunk as well, but this is what I did to get NPS event logging into Splunk.

First, NPS was set up to log to SQL. See https://technet.microsoft.com/en-us/library/dd197595%28v=ws.10%29.aspx and other documents on how to do this. (The SQL DB was set up by someone other than me so I can't provide good details)

Second, I installed the Splunk DBConnect application. With that I set up a DB connection to the NPS SQL database, and then defined database input of the type 'tail' with a "Rising Column" of the id field from the database. I didn't specify any special SQL query so I get all events, and I used the 'auto' interval method.

This seems to be working just fine.

0 Karma

ppablo
Retired

Hi @bucfan609

Just wanted to make sure, but are you actually referring to the Splunk for Wireless Networks app (https://apps.splunk.com/app/980/ ) in this post, or was that on accident? If not, then I'll remove that tag for you.

0 Karma

bucfan609
New Member

I am sorry. I didn't meant to tag that.

0 Karma

ppablo
Retired

No problem, just fixed it for ya.

0 Karma

mliveri
New Member

Did you manage to get it working? what did you do to achieve it if you did get it working as im currently trying to evaluate on what data to create a dashboard for failures and login failures and lockouts.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...