Splunk Search

How to generate a search to find a local account added to admin group within one hour?

New Member

How can I find if a local account/user has been created and then added to the admin/domain admin group within a span of certain time such as 1 hour?
Local user account codes
EventCode=4720 OR EventCode=4721
Admin account codes
EventCode=4732 OR EventCode=4728 OR EventCode=4756
I am not able to structure it right?
Can anybody help

0 Karma

New Member

Have you checked out gosplunk.com? There may be some relevant queries you can use as a starting point (e.g., http://gosplunk.com/?s=Local+user+admin+group&cat=0)

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!