Security

Search for Windows EventCode not caused by a Logon attempt

mitchmd1
New Member

We have to search for EventCode 4656 for Windows 7 and 2008 Server.

A lot of the 4656 are caused by logons (4624) and is there a way to search for 4656 and only show ones that are not caused by a logon.

Lets say, dont show any 4656 within 30 seconds of a 4624.

Thanks

0 Karma

JSapienza
Contributor

You might be able to filter your result set by looking at the "Process Name:" field. Or post a few of your offending events to get a better look as to what you need to filter out .

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...