Splunk Search

Setup an alert for Changing password parameters?

iamsplunker
Communicator

Hello Splunkers,

I wanted to setup an alert for changing password parameters for ex, we have policy of 15 min characters which includes at least 1 number lowercase , 1 number uppercase , 1 special characters I want an alert to trigger if someone modifies this password rule.

 

 Thanks!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Where do you have this policy? In what system? And how is it connected with Splunk?

0 Karma

iamsplunker
Communicator

Thanks for your response @PickleRick 
We defined the policy in Splunk cloud SH.

Connection SHC -- IDXR -- FORWARDER

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. If you mean the password policy within the Splunk itself, you should be able to find it in the _configtracker index (I'm not sure if it's available for Cloud but I assume it is) - look for changes to authorize.conf file.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...