Hi All,
Can anyone help me to get the query for short lived account with the condition of user create and delete the account on active directory within 10 minutes… I don’t need the logs of user creation and deletion
Thanks in advance.
Hi @Deeksha,
if you install the Splunk Security Essentials App (https://splunkbase.splunk.com/app/3435) you can find all the information you need and also the requirements (about data) and the search itself.
Ciao.
Giuseppe