Alerting

How to create an alert for login attempts to Splunk Web?

summitsplunk
Communicator

I'm trying to see if there's a way to monitor who accesses Splunk and create alerts around that?

Tags (1)
1 Solution

skoelpin
SplunkTrust
SplunkTrust

Try this. It will look at all login attempts and trigger an alert when a user has more than 1 login failure

index=_audit login action=success OR action=failure
| stats count by user, action
| search action=failure count>1

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

Try this. It will look at all login attempts and trigger an alert when a user has more than 1 login failure

index=_audit login action=success OR action=failure
| stats count by user, action
| search action=failure count>1
Get Updates on the Splunk Community!

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...