Splunk Search

5 and above login failures

robK123
Explorer

I have managed to create a search that finds users that have failed to login within the last 24 hours but I want to only see users who fail to login 5 or more times.

This is what I have so far:

source="secure" sshd "pam_ldap: error trying to bind as user" | top uid

How can I make it so it onlys shows 5 or more failed logins per user?

Thanks,

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You could filter the results of top like so:

... | top uid | where count >= 5

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could filter the results of top like so:

... | top uid | where count >= 5
0 Karma

robK123
Explorer

That worked perfectly thanks.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...