Security

How to mac address for a particular user?

kiran_mh
Explorer

Hi,

I wanted to get the mac address for a particular user, user=paraga

The problem was the user account got locked out
so we want to know which caused this issue...

Thanks in advance.

Tags (1)

skoelpin
SplunkTrust
SplunkTrust

I would agree with @pgreer that it would depend on what type of data is being indexed.. If it's XML data then you could use the KV_MODE=xmlon your props.conf and break them into key-value pairs.

You could also extract the field user and use that field in your query. An example would be, you pasting the mac address into the search and seeing the value for the user field

index=foo 01-23-45-67-89-ab-cd-ef | top user

Try this to extract the field user, the field will pop up on the left side under interesting fields

... | rex (?P<user>(?<=user=)\w+)

pgreer_splunk
Splunk Employee
Splunk Employee

Depends on the data being indexed. What are you indexing that might be of use to find such a tidbit of information?

BTW: A user is not necessarily tied to a MAC address. If that user always uses a single system (i.e. it is their desktop or laptop that they solely use for work and they don't log into any other workstations in your organization or from home VPN) then one could say that the MAC address(es) on that system that they solely use can be attributed to activity to/from that user. So I would suggest at first identifying the machine in the data you are indexing that the user solely uses, then use that as a basis to search for data that would identify the MAC address(es) of the system that the user uses.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...