Security

Search for Windows EventCode not caused by a Logon attempt

mitchmd1
New Member

We have to search for EventCode 4656 for Windows 7 and 2008 Server.

A lot of the 4656 are caused by logons (4624) and is there a way to search for 4656 and only show ones that are not caused by a logon.

Lets say, dont show any 4656 within 30 seconds of a 4624.

Thanks

0 Karma

JSapienza
Contributor

You might be able to filter your result set by looking at the "Process Name:" field. Or post a few of your offending events to get a better look as to what you need to filter out .

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...