Splunk Search

How do you identify all accounts not automatically locked after 5 consecutive failed log in attempts?

sahiltcs
Path Finder

I need to check how to identify all technical accounts that are not automatically locked after 5 consecutive failed log in attempts

Please help with the query

Thanks,
Sahil

0 Karma
1 Solution

lakshman239
Influencer

When an account gets locked out, Active Directory sends out EventCode=4740. So, if you are indexing AD security logs, you could check for lock-outs using

index=wineventlog EventCode=4740 Account_Name=* ..... shows all locked accounts.

index=msad | timechart span=5m sum(badPwdCount) AS total by sAMAccountName ... gives count of lockouts for each user.

So, you can run the 2nd search to check for lockout counts and check if you have a 4740 event for that user. If there is no record, that could potentially indicate an account not getting locked out.

View solution in original post

0 Karma

lakshman239
Influencer

When an account gets locked out, Active Directory sends out EventCode=4740. So, if you are indexing AD security logs, you could check for lock-outs using

index=wineventlog EventCode=4740 Account_Name=* ..... shows all locked accounts.

index=msad | timechart span=5m sum(badPwdCount) AS total by sAMAccountName ... gives count of lockouts for each user.

So, you can run the 2nd search to check for lockout counts and check if you have a 4740 event for that user. If there is no record, that could potentially indicate an account not getting locked out.

0 Karma

sahiltcs
Path Finder

I checked Above query but not worked , Can you give me proper query so that I can test, May be query is right but some argument is missing.

Thanks,
Sahil

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...