Splunk Search

How to create a search for Account Creation Event ID 4720?

lsufan861
New Member

I'm a novice user to Splunk and need a simple index search for account creation, time, and creator.  I'm on  closed domain and don't have the typical add ons.  Thank you in advance.

Labels (1)
Tags (1)
0 Karma

General_Talos
Path Finder

Try this if this helps

 

index=* source="WinEventLog:Security" (EventCode=4720 OR EventCode=624)
    | eval CreatedBy = mvindex(Account_Name,0) 
    | eval New_User = mvindex(Account_Name,1) 
    | search CreatedBy=*
    | table _time EventCode CreatedBy New_User

cwheeler33
Explorer

this post saved me so much time!!!
Thank you

note1: Only need EventCode=624 if you have Windows 2008 or older systems.
note2: don't need this line, but the rest is perfect.

| search CreatedBy=*

 

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...