All Apps and Add-ons

Cisco ACS failed logins to corp wifi

Ghanayem1974
Path Finder

I am not sure how to capture the device info associated with the MAC address? for example, apple device\mac address. I also want to capture the type of failure, for example Invalid Password or Wrong Password. The calling station id is the mac address of the device in question but i don't know how to capture the name, i am not looking for the name of the AP or WLC. Thanks.
index=acs action=failure | stats count by user NetworkDeviceName "Calling_Station_ID" | rename "Calling_Station_ID" AS MAC | sort -count | where count > 100

Tags (1)
0 Karma

deepashri_123
Motivator

Hey@Ghanayem1974,

Can you share the sample format of the logs and what exactly you want to extract?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...