Does anyone have examples of how to use Splunk to check for activity from expired users?
The Splunk Product Best Practices team helped produce this response. Read more about example use cases in the Splunk Platform Use Cases manual.
In this use case, we'll explore how to use Splunk Enterprise Security to alert when an event is discovered from a user associated with an expired identity.
This use case depends on asset and identity data. Use the Add asset and identity data to Splunk Enterprise Security procedure to let Splunk Enterprise Security correlate asset and identity information with events to enrich and provide context to the data.
This scenario uses the Incident Review dashboard in Splunk Enterprise Security and underlying correlation searches. Use the following procedure to discover incidents:
Review the Overview of Incident Review in Splunk Enterprise Security in Splunk docs for guidance on how to triage and act on resulting incidents. If no results appear, there may not be any notable notable events. However, you may need to enable correlation searches.
Watch the following video to see how the Use Case Library in Splunk Enterprise Security can strengthen your security posture and reduce risk with readily available, usable and relevant content.
View solution in original post
Added related video.