Splunk Search

How to search and report when a user logs in and out from a keyboard 'Login Type 2'?

kevind5
New Member

I need to search my index to determine when a user physically logs on to our network. Event 4624 queries result in all logon events mainly Type 3. I need to report when 'Joe' sat down and logged in and when 'joe' logs out from his workstation Logon Type 2. Thanks

0 Karma

DalJeanis
Legend

Just do this in verbose mode

index=foo EventID=4624 | head 5

Look at the events, and find the name of the extracted field that contains the Logon Type. Add it to your query.

(On my system, I'd just add EventID=4624 Logon_Type=2 to the query. )

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...