Reporting

False user account lockout

brpsingara
Explorer

Hello,
I am receiving the false user account lockout report on particular user account.
I am getting one user account lockout report daily with count of 25 to 40. But the user is active state, he is able to login and doing his daily tasks.and I cross checked with system administrator team, is the user active or locked. They told the user us active. From July 3rd I am receiving, user account same, host same, only
I don’t know why splunk triggering that particular user account lockouts.

Here the code which I am using for daily report.

Sourcetype=WinEventLog.Security Event=4740
| stats count by Accout_Name
|sort – count 
| rename count as “Accout Lockouts”

If I search particular user account below event codes are also showing,

user=”Kiran”

A user account was locked out - 4740
A new process had been created - 4688
The state of a transaction has changed – 4985
Source WinEventLog.Security
Sourcetype WinEventLog.Security
Host SYS-MACHINE1, SYS-MACHINE2, SYS-MACHINE3
Action modified & success
Msad_action 35

May I know is the problem with splunk or anything else ?

Tags (1)

nick405060
Motivator

It is very interesting that you posted this. My company is having the exact same problem this week; it is not a Splunk problem it is a problem with our larger IT infrastructure. Can you keep me updated, because we do not understand why lockout events are being generated when the user is not actually locked out.

On your end, it is likely not a Splunk problem either, as Splunk is merely ingesting the 4740 logs from your (presumably) domain controller. You can look at the contents of the events and the timestamps to verify there is no duplication or reingestion.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...