Alerting

We try to filter login Alert to other team via email using "NOT" whoever login to server

Mplunk2work
Observer

index=12345_ati_pia NOT Logon_Type!=10 NOT Account_Name=abc* NOT Account_Name=te* (EventCode=5421 Logon_Type=10 NOT Target_Server_Name=localhost) OR (EventCode=5421 NOT Account_Name=$) NOT Account_Name=DNA NOT Account_Name=te* NOT Account_Name=SYSTEM NOT Account_Name=BladeLogicCAMR NOT Account_Name=abckk1 NOT Account_Name=IOWADBQ NOT Account_Name=cored1 NOT Account_Name=ANON* NOT Account_Name=dmvcars

Tags (1)
0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

Hi @mplunk2work. In general, your question has a greater chance of being answered by experts in the Answers community when when you provide as much information and context as possible. Thanks!

0 Karma

skoelpin
SplunkTrust
SplunkTrust

What's your question?

Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...