Splunk Search
Highlighted

How to generate a search for the creation of admin accounts?

New Member

need a search for creation of admin accounts. For both Windows and Linux. Domain-level accounts. Thanks

0 Karma
Highlighted

Re: How to generate a search for the creation of admin accounts?

Splunk Employee
Splunk Employee

@MastaMia - In general, your question has a greater chance of being answered by experts in the Answers community when when you provide as much information and context as possible.

0 Karma
Highlighted

Re: How to generate a search for the creation of admin accounts?

SplunkTrust
SplunkTrust

for windows look for events 4720 account was created and 4732 (or related) account was added to a global security group
read here and then move to related events (from the link)
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4720
linux has less verbose logging than windows but i can think of some ways to monitor that.
most of the time each user will have its own home directory and therefore if you see a new source it means a new user.
also there are ways to monitor the suduers list on linux
hope it helps a little

0 Karma
Highlighted

Re: How to generate a search for the creation of admin accounts?

SplunkTrust
SplunkTrust

interesting idea. How would you find the home directories?

0 Karma