Data Model Authentication sucessful splunk query alerts

Path Finder

Please I need  help with a detailed splunk Data accelerated data model authentication query for sucessful  login alerts using a | tstats summariesonly=true . The query should have count threshold.  The query should cover all products and vendors names used in the environment. It is not only successful login based on windows.

Labels (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!