Splunk Search

How to create a table that shows multiple failed logins on the same workstation by different usernames?

bakalon
Explorer

Hello,
So I'm looking to a use case where I have to create a table that shows multiple failed logins on the same workstation by different usernames.

Here's what I have so far:

index=windows* sourcetype=WinEventLog:Security EventCode=4625 | eval AccountName=mvindex(Account_Name, 1) | | stats  values(AccountName) by Workstation_Name

That shows all accounts that failed to log in. I want the result where there are multiple failed accounts on the same workstation. So something like ....| where AccountName > 1.

Please let me know if this makes sense. Thanks!

0 Karma
1 Solution

somesoni2
Revered Legend

Try like this

index=windows* sourcetype=WinEventLog:Security EventCode=4625 | eval AccountName=mvindex(Account_Name, 1) |  stats  values(AccountName) as Accounts by Workstation_Name | where mvcount(Accounts)>1

View solution in original post

somesoni2
Revered Legend

Try like this

index=windows* sourcetype=WinEventLog:Security EventCode=4625 | eval AccountName=mvindex(Account_Name, 1) |  stats  values(AccountName) as Accounts by Workstation_Name | where mvcount(Accounts)>1

bakalon
Explorer

Dude!!! Thank you very much. I was not aware of the mvcount expression. This worked like a charm. Cheers!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...