Getting Data In

How are other users utilizing Splunk to monitor privileged account usage in Windows/*nix environments?

New Member

How are other users utilizing Splunk to monitor privileged account usage in Windows/*nix environments? I'm looking for dashboards/report ideas and any other alerts that others have created for enterprise monitoring that we may be able to adapt. Thanks!

0 Karma

Champion

The ES app has an example of how this can be done but it requires a paid POC.

A simple way to do it would be to use a lookup file containing your privileged account details (name, email address, userid, etc) and run a query that uses that lookup file to find a match.

0 Karma