All Apps and Add-ons

How to edit my search to create a table to show User, Failed Authentication Attempts, Domain, and Lockout status?

HCadmins
Communicator

Hi Splunkers:

I am trying to create a simple table that has the columns: User, Failed Authentication Attempts, Domain, and Locked?

User would be, of course the user
Failed Authentication Attempts would show up if greater than 3
Domain would show the domain they were attempting to authenticate against
Locked would be a yes or no value

It's the locked out part I am having trouble with.

Here is my search:

index=wineventlog Account_Domain=* ("EventCode=4625" OR "EventCode=4740")  | head 10 | stats count by user Account_Domain | search count>3 | table user count Account_Domain | rename user as "User" count as "Failed Authentication Attempts" Account_Domain as "Domain"
0 Karma
1 Solution

sundareshr
Legend

See if this helps

index=wineventlog Account_Domain=* ("EventCode=4625" OR "EventCode=4740") | head 10 | stats count count(eval(EventCode=4740)) as LockedCount by user Account_Domain | search count>3 | eval Locked=if(LockedCount>1, "yes", "no")  | table user count Account_Domain Locked | rename user as "User" count as "Failed Authentication Attempts" Account_Domain as "Domain"

View solution in original post

0 Karma

sundareshr
Legend

See if this helps

index=wineventlog Account_Domain=* ("EventCode=4625" OR "EventCode=4740") | head 10 | stats count count(eval(EventCode=4740)) as LockedCount by user Account_Domain | search count>3 | eval Locked=if(LockedCount>1, "yes", "no")  | table user count Account_Domain Locked | rename user as "User" count as "Failed Authentication Attempts" Account_Domain as "Domain"
0 Karma

HCadmins
Communicator

Error in 'eval' command: The arguments to the 'if' function are invalid.

0 Karma

sundareshr
Legend

Fixed typo

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...