Monitoring Splunk

How to create use case that would detect when admin password modified/changed?

DanAlexander
Communicator

Hi All,

I need to create a Use Case that would detect Admin user/s changing their own password.

So far I have:

index=XXX EventCode=4724

| where user=src_user AND src_user_category="privileged" AND  user_category="privileged"

not sure how to go around as this is not doing the search I want.

Any help much appreciated!

Thanks all

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain what is meant by "not doing the search I want".  What do you want and what do you get?

My WinEventLog doesn't have the user_category and src_user_category fields.  Are you sure yours does?  In the past, I've had to detect admin accounts based on a naming convention.  For example:

index=wineventlog EventCode=4724 user!="*$" user="adm_*"
| where user=src_user

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...