Splunk Search

Top 10 same failed login on different computer

arkonner
Path Finder
 
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The specifics depend on your data, but this is the general idea:

<search for failed logins> | stats count as Failures by username | top Failures | ...
---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Do you have a question?

---
If this reply helps you, Karma would be appreciated.
0 Karma

arkonner
Path Finder

The title is the question, how to do a search like this

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...