Getting Data In

Monitoring Event Logs

yashaswinig2210
Engager

Hi,

I'm trying to pull the event logs when an account is being locked in Active Directory, but I could see multiple entries for single account, one entry for each 1 or 2 hrs . Could please help me in understanding why duplicate entries are being generated in splunk?

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...