Hello
any ideas how can i check rdp attempts or connections in Splunk? many thanks
Hello
I have windows security logs on host. I remember when I just started with Splunk and I had my Splunk lab and I had some kind of security free add on ( can't remember) where I was able to see attempts on port 3389 (dashboard)
Are you collecting windows security logs from both the src and dest host?