Splunk Search
Highlighted

Query to get admin group log-in events

Path Finder

Is there is any splunk query to get all login events for all users from administrators group.

0 Karma
Highlighted

Re: Query to get admin group log-in events

Contributor

Hi,
This depends on our authentication method are you using local or LDAP/AD logins? Either way I think you'd need to use a subsearch that first looks for the user logins and then determines if they are part of the admin group "like" this:

source=<login events> user=* [source=<table or log that determines admin group membership> | fields user] | stats count by user