Splunk Enterprise Security

Is it possible to use splunk to automate account unlocking but limit it to a set number of times?

dschneider
Engager

My use case is that we pay a vendor to do unlocks after hours for us. I do not want to turn on the AD setting to unlock an account after x amount of time because of brute force issues.

I was looking to use the Splunk (cloud) alerts we have for when a user gets locked to trigger a powershell to unlock it. But only say 3 times before it alerts and leaves it locked.

I have looked all over but have just parts of my total. The Alerting I have nailed down. It's the action I don't.

We have Splunk Cloud and Splunk ES I am ok if the solution is another add-on.

Does anyone have a suggestion?

Thanks,

Dave

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...