Splunk Search

Setup an alert for Changing password parameters?

iamsplunker
Communicator

Hello Splunkers,

I wanted to setup an alert for changing password parameters for ex, we have policy of 15 min characters which includes at least 1 number lowercase , 1 number uppercase , 1 special characters I want an alert to trigger if someone modifies this password rule.

 

 Thanks!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Where do you have this policy? In what system? And how is it connected with Splunk?

0 Karma

iamsplunker
Communicator

Thanks for your response @PickleRick 
We defined the policy in Splunk cloud SH.

Connection SHC -- IDXR -- FORWARDER

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. If you mean the password policy within the Splunk itself, you should be able to find it in the _configtracker index (I'm not sure if it's available for Cloud but I assume it is) - look for changes to authorize.conf file.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...