Security

Multiple Failed logins followed by a succesful login from the same user account

ajeeshneelamkav
New Member

Inorder to track multiple login failure to a Linux machine followed by a successful login from the same user account. Howe can we achieve this using search query?

Similar way
multiple login failure to a Linux machine followed by a successful login from the same IP address.

Any help will be appreciated.

Log source: Linux logs

Tags (1)
0 Karma

ajeeshneelamkav
New Member

The success event should search only if there are multiple failure from the same account. This will trigger or result even though a success event occurred in between multiple failure events?

0 Karma

kml_uvce
Builder

index the log file which have all users/ip details of login successful and failure.

serach
your search|transaction user|table user status

where user is the user id in the logs and status is the failed or successful value , you need to extract these fields(user, status) from the logs.

change user with ip address to check successful login from the same IP address

0 Karma

ajeeshneelamkav
New Member

The success event should search only if there are multiple failure from the same account. This will trigger or result even though a success event occurred in between multiple failure events?

0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...