Alerting

We try to filter login Alert to other team via email using "NOT" whoever login to server

Mplunk2work
Observer

index=12345_ati_pia NOT Logon_Type!=10 NOT Account_Name=abc* NOT Account_Name=te* (EventCode=5421 Logon_Type=10 NOT Target_Server_Name=localhost) OR (EventCode=5421 NOT Account_Name=$) NOT Account_Name=DNA NOT Account_Name=te* NOT Account_Name=SYSTEM NOT Account_Name=BladeLogicCAMR NOT Account_Name=abckk1 NOT Account_Name=IOWADBQ NOT Account_Name=cored1 NOT Account_Name=ANON* NOT Account_Name=dmvcars

Tags (1)
0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

Hi @mplunk2work. In general, your question has a greater chance of being answered by experts in the Answers community when when you provide as much information and context as possible. Thanks!

0 Karma

skoelpin
SplunkTrust
SplunkTrust

What's your question?

Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...