Getting Data In

How are other users utilizing Splunk to monitor privileged account usage in Windows/*nix environments?

NateStreet
New Member

How are other users utilizing Splunk to monitor privileged account usage in Windows/*nix environments? I'm looking for dashboards/report ideas and any other alerts that others have created for enterprise monitoring that we may be able to adapt. Thanks!

0 Karma

the_wolverine
Champion

The ES app has an example of how this can be done but it requires a paid POC.

A simple way to do it would be to use a lookup file containing your privileged account details (name, email address, userid, etc) and run a query that uses that lookup file to find a match.

0 Karma
Get Updates on the Splunk Community!

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...