Splunk Search

How to try to search for new MFA factors with DUO?

JR_Akaviri
Engager

I'm trying to find any new MFA factors(DUO) used by any user in the past X days in order to create an alert.  As an example a user uses push notifications every login for X-1 days then on the X day they use passcode, I want to trigger an alert or show up in a report.

 

I'm having an issue wrapping my head around on how to search for the first instance of a new value for the field factor in the past X days without specifying the expected value ahead of time (some users use push, some use phone call, some use pass code I just want to know when they use something different.  Any assistance or tips would be helpful.

Labels (1)
Tags (3)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Pro tip:

  1. Illustrate the data you re trying to search (sanitize as necessary).  This is a Splunk board.  Most people will not know what your DUO data look like.  
  2. Illustrate attempted code you have made so far to improve others' understanding of your intentions.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...