Security

How to check if an account or username is locked through Splunk? This is not related to window login or Unix Login...

bsaujla131984
Path Finder

We have been issues when application stops responding , when a particular account gets locked.

I would like to create an alert to overcome this issue.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Is the application logging account lockouts to Splunk? If so, you can create an alert when a lockout event is detected. If the application does not log to Splunk then Splunk has no way to know the account has been locked out and cannot alert you.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...