Splunk Search

Setup an alert for Changing password parameters?

iamsplunker
Communicator

Hello Splunkers,

I wanted to setup an alert for changing password parameters for ex, we have policy of 15 min characters which includes at least 1 number lowercase , 1 number uppercase , 1 special characters I want an alert to trigger if someone modifies this password rule.

 

 Thanks!

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Where do you have this policy? In what system? And how is it connected with Splunk?

0 Karma

iamsplunker
Communicator

Thanks for your response @PickleRick 
We defined the policy in Splunk cloud SH.

Connection SHC -- IDXR -- FORWARDER

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. If you mean the password policy within the Splunk itself, you should be able to find it in the _configtracker index (I'm not sure if it's available for Cloud but I assume it is) - look for changes to authorize.conf file.

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...