Splunk Search

Use Case sAMAccountName changes in domain controller

shanaz
Engager

Hi,

want to create a search to find anyone who does changes to the sAMAccountName 

So sAMAccountName could be sAMAccountName=cdf or sAMAccountName=abc

sAMAccountName=abc  if anyone changes this to sAMAccountName=abc1 triggers an alert. 

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Windows event 4738 should tell you if the account name changed.  Look for SAM_Account_Name under Changed_Attributes.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...