Splunk Search

Search to find unauthorized host(s) last login date

cjsweeney1
Explorer

Hi looking for a search to find any unauthorized systems that are sitting on a network and the last login date.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To find unauthorized systems you'll first need a list of the authorized systems, perhaps in a lookup file. Then search to find ALL systems on your network and compare that list to the authorized list. The difference is the unauthorized systems.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cjsweeney1
Explorer

Hey Rich,

You know a search string to find a particular hosts last ip "pull" is... I'm wondering if the last time it had a DHCP timestamp assigned is all I will be able to get.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't know that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cjsweeney1
Explorer

Hmmm.... could work. Could that lookup file be automatically updated? I was hoping enterprise security would have a report like this built-in.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it's possible to automatically update the lookup file.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...