Splunk Search

Use Case sAMAccountName changes in domain controller

shanaz
Engager

Hi,

want to create a search to find anyone who does changes to the sAMAccountName 

So sAMAccountName could be sAMAccountName=cdf or sAMAccountName=abc

sAMAccountName=abc  if anyone changes this to sAMAccountName=abc1 triggers an alert. 

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Windows event 4738 should tell you if the account name changed.  Look for SAM_Account_Name under Changed_Attributes.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...