Splunk Search

How to generate a search for the creation of admin accounts?

MastaMia
New Member

need a search for creation of admin accounts. For both Windows and Linux. Domain-level accounts. Thanks

0 Karma

adonio
Ultra Champion

for windows look for events 4720 account was created and 4732 (or related) account was added to a global security group
read here and then move to related events (from the link)
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720
linux has less verbose logging than windows but i can think of some ways to monitor that.
most of the time each user will have its own home directory and therefore if you see a new source it means a new user.
also there are ways to monitor the suduers list on linux
hope it helps a little

0 Karma

DalJeanis
Legend

interesting idea. How would you find the home directories?

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@MastaMia - In general, your question has a greater chance of being answered by experts in the Answers community when when you provide as much information and context as possible.

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...