Splunk Search

How to generate a search to find a local account added to admin group within one hour?

abdul_jabbar
New Member

How can I find if a local account/user has been created and then added to the admin/domain admin group within a span of certain time such as 1 hour?
Local user account codes
EventCode=4720 OR EventCode=4721
Admin account codes
EventCode=4732 OR EventCode=4728 OR EventCode=4756
I am not able to structure it right?
Can anybody help

0 Karma

johnpusey
New Member

Have you checked out gosplunk.com? There may be some relevant queries you can use as a starting point (e.g., http://gosplunk.com/?s=Local+user+admin+group&cat=0)

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...