I am trying to get the System access attempts with invalid credentials. Folks with unknown user names. I am using the following search part: index=_internal sourcetype=splunkd user=* component=UserManagerPro
There are a ton of messages with the following:
message="user=\"system\" had no roles" and message="user=\"nobody\" had no roles"
I believe they can just be filtered out and I am using version 7.0.4