Alerting

How to configure NPS to forward login error logs to Splunk server and set up an alert when accounts are locked?

bucfan609
New Member

Good morning...

I am very new to Splunk (I am sure that this is how a lot of people begin their posts....but anywho) and am trying to get info from an NPS server to a newly created splunk server. I need to troubleshoot some wireless issues with an Aerohive wireless infrastructure. I have the APs sending syslog data to Splunk and although it does in fact send info there, I need stuff specifically with login errors and possibly the ability to create alerts when accounts are locked.

Thanks in advance for the help.

0 Karma

patmalone_jdsuc
New Member

I am new to Splunk as well, but this is what I did to get NPS event logging into Splunk.

First, NPS was set up to log to SQL. See https://technet.microsoft.com/en-us/library/dd197595%28v=ws.10%29.aspx and other documents on how to do this. (The SQL DB was set up by someone other than me so I can't provide good details)

Second, I installed the Splunk DBConnect application. With that I set up a DB connection to the NPS SQL database, and then defined database input of the type 'tail' with a "Rising Column" of the id field from the database. I didn't specify any special SQL query so I get all events, and I used the 'auto' interval method.

This seems to be working just fine.

0 Karma

ppablo
Retired

Hi @bucfan609

Just wanted to make sure, but are you actually referring to the Splunk for Wireless Networks app (https://apps.splunk.com/app/980/ ) in this post, or was that on accident? If not, then I'll remove that tag for you.

0 Karma

bucfan609
New Member

I am sorry. I didn't meant to tag that.

0 Karma

ppablo
Retired

No problem, just fixed it for ya.

0 Karma

mliveri
New Member

Did you manage to get it working? what did you do to achieve it if you did get it working as im currently trying to evaluate on what data to create a dashboard for failures and login failures and lockouts.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...