Splunk Enterprise

Splunk counting duplicate events for failed logon

bayman
Path Finder

When the below search is ran, it'll count duplicate failed logons for all users. How do I exclude duplicates in a count?

eventtype=msad-failed-user-logons
(host="*")|fields
_time,signature,src_ip,src_host,src_nt_host,src_nt_domain,user,Logon_Type|stats
count by
user,src_nt_domain,src_ip,|sort
-count|rename user as "Username", src_nt_domain as "Domain", src_ip as
"IP Address"

0 Karma
1 Solution

DalJeanis
SplunkTrust
SplunkTrust

Try this -

eventtype=msad-failed-user-logons (host="*")
| fields_time, signature, src_ip, src_host, src_nt_host, src_nt_domain, user, Logon_Type
| dedup signature
| stats count by user, src_nt_domain, src_ip,
| sort - count
| rename user as "Username", src_nt_domain as "Domain", src_ip as "IP Address"

Based on the assumption that the dups will have the same signature.

View solution in original post

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @bayman, if @DalJeanis's solution worked then please don't forget to accept their answer to award karma points and close the question. 🙂

DalJeanis
SplunkTrust
SplunkTrust

Try this -

eventtype=msad-failed-user-logons (host="*")
| fields_time, signature, src_ip, src_host, src_nt_host, src_nt_domain, user, Logon_Type
| dedup signature
| stats count by user, src_nt_domain, src_ip,
| sort - count
| rename user as "Username", src_nt_domain as "Domain", src_ip as "IP Address"

Based on the assumption that the dups will have the same signature.

0 Karma

bayman
Path Finder

I dedup _time instead and it seemed to work better. Thanks

DalJeanis
SplunkTrust
SplunkTrust

@bayman - thanks for letting us know what worked. Interesting that the signature might be different between two duplicate events. Must mean something different from what I was guessing.

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...