I have the below use case to detect Cleartext Passwords at rest
| from datamodel:"Compute_Inventory"."Cleartext_Passwords" | stats max(_time) as "lastTime",latest(_raw) as "orig_raw",values(tag) as "tag",count by "dest","user","password"
This datamodel runs the below search query
(`cim_Compute_Inventory_indexes`) tag=inventory (tag=cpu OR tag=memory OR tag=network OR tag=storage OR (tag=system tag=version) OR tag=user OR tag=virtual) tag=user password=*
But I am not getting any results. There are events like below which says password=x (I know its fetching from /etc/passwd) and not cleartext password, but still, I do not see any results when I do a pivot. Can someone please tell me why?
When I remove password=* and do a preview, I see password=x. Password is properly being extracted as a separate field when I run the query for its sourcetype and index.