I'm new to Splunk and was hoping someone could point me in the right direction for some support.
I use the Account Lockout Dashboard in order to understand why users are locking out their accounts. Lock outs can be caused by incorrect logins from the LAN, mobile devices, users connected to the VPN, etc.
Are there any documents or tutorials that explain the differences between the Windows Logon Failures Panel, Netlogon Logon Failures Panel, and APM Logon Failures Panel? Or perhaps there is a general tutorial for the Account Lockout Dashboard or newcomers to Splunk?