Security

How can I search for a user's Incorrect Password?

jctst714
New Member

Hello,

I have a user that occasionally experiences a lack of connectivity over a VPN into one of my servers. He can connect most of the time, but there are instances where he's unable to remote in with RDP.

How can I search for the user/Active Directory (already set up in Splunk environment) to see if there are any incorrect logins? It's a simple query, but I'm new to the system.

Thank you in advance.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

index=wineventlogs EventType=4625
You can look at the Failure_Reason field to determine why the account failed.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...