Security

Is it possible to lock a Splunk user account on failed logins?

sc0tt
Builder

Is it possible to lock a Splunk user account if there are multiple failed login attempts? I've created an alert for such events, but was wondering if there was a way to lock an account as well.

Tags (4)
0 Karma

m4him7
Path Finder

We use LDAP lookup which will lock the domain account based on your policy.

khyoung7410
Communicator

Is there any other way besides LDAP?

0 Karma

sc0tt
Builder

Thanks, we don't have LDAP set up but it seems it may be the only way to accomplish this.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...