Splunk Search

How many login attempts can be seen in the logs for username=admin?

ravik453
New Member

I'm trying to complete the lab for my cybersecurity course. I googled few thing for this question, but this question doesn't seem to accept the answer. It is a course from Immersive labs. May be i'm doing something wrong or any problem with my query. I'm not sure.  I've used the query:-

index="_audit" action=* info=*
| stats count by user

Need your help with this to search login attempts for username=admin.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The key to using Splunk is understanding your data. You should examine the log / event data you have available to you to determine which part of the event will help you with your usecase. I suspect this is the purpose of the exercise. You should have been provided with all the necessary information to complete this.

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...