Splunk Search

Search to find unauthorized host(s) last login date

cjsweeney1
Explorer

Hi looking for a search to find any unauthorized systems that are sitting on a network and the last login date.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To find unauthorized systems you'll first need a list of the authorized systems, perhaps in a lookup file. Then search to find ALL systems on your network and compare that list to the authorized list. The difference is the unauthorized systems.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cjsweeney1
Explorer

Hey Rich,

You know a search string to find a particular hosts last ip "pull" is... I'm wondering if the last time it had a DHCP timestamp assigned is all I will be able to get.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't know that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cjsweeney1
Explorer

Hmmm.... could work. Could that lookup file be automatically updated? I was hoping enterprise security would have a report like this built-in.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it's possible to automatically update the lookup file.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...