Alerting

We try to filter login Alert to other team via email using "NOT" whoever login to server

Mplunk2work
Observer

index=12345_ati_pia NOT Logon_Type!=10 NOT Account_Name=abc* NOT Account_Name=te* (EventCode=5421 Logon_Type=10 NOT Target_Server_Name=localhost) OR (EventCode=5421 NOT Account_Name=$) NOT Account_Name=DNA NOT Account_Name=te* NOT Account_Name=SYSTEM NOT Account_Name=BladeLogicCAMR NOT Account_Name=abckk1 NOT Account_Name=IOWADBQ NOT Account_Name=cored1 NOT Account_Name=ANON* NOT Account_Name=dmvcars

Tags (1)
0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

Hi @mplunk2work. In general, your question has a greater chance of being answered by experts in the Answers community when when you provide as much information and context as possible. Thanks!

0 Karma

skoelpin
SplunkTrust
SplunkTrust

What's your question?

Get Updates on the Splunk Community!

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...