Deployment Architecture

Help with Windows dormant enable search

debjit_k
Path Finder

Hi All, 

I want to create a use case where the account is inactive for 60 days and it got enable after 60 days.. 

I tied to draw ta logic but not sure whether query is correct or not.

Can somebody please modify the query if it required some change 

index=wineventlog EventCode=4624 user=”*@xyz.com" earliest= -60d latest = now() | transaction user maxspan=60d search (EventCode!=)

 

Thank you 

Labels (4)
0 Karma
Get Updates on the Splunk Community!

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...