Security

Search for Windows EventCode not caused by a Logon attempt

mitchmd1
New Member

We have to search for EventCode 4656 for Windows 7 and 2008 Server.

A lot of the 4656 are caused by logons (4624) and is there a way to search for 4656 and only show ones that are not caused by a logon.

Lets say, dont show any 4656 within 30 seconds of a 4624.

Thanks

0 Karma

JSapienza
Contributor

You might be able to filter your result set by looking at the "Process Name:" field. Or post a few of your offending events to get a better look as to what you need to filter out .

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...