I have an employee who keeps getting locked out. I wanted to know how to put a script in to find out which device is getting locked out.
That search shows some who are locked out and some people who log in to a device. It shows some of everything. I wish it would determine who is locked out instead of stating no for everything.
Please share anonymised examples of your log events.
Do you have logs ingested into Splunk?
Can you share some anonymised examples of the events you are trying to detect?