Security

How to check if an account or username is locked through Splunk? This is not related to window login or Unix Login...

bsaujla131984
Path Finder

We have been issues when application stops responding , when a particular account gets locked.

I would like to create an alert to overcome this issue.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Is the application logging account lockouts to Splunk? If so, you can create an alert when a lockout event is detected. If the application does not log to Splunk then Splunk has no way to know the account has been locked out and cannot alert you.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...