Splunk Search

Usernames Failed to Login against an IP Address | which other IP Addresses has that Username Failed to login against?

JgTheGreat
Engager

Hello,

I'm looking for a query, which looks for successful [ or unsuccessful ] brute force attempts, and then to take the Username that was [ or unsuccessfully/successfully logged in and then automatically return which other (if any) IP's that account was logged into.

Virtual beers and a high five on offer here 😄

KJG

Tags (1)
0 Karma

mayurr98
Super Champion
index=your_index status=succes OR status=unsuccessful | stats values(srcip) by users status

If you give me sample event and field names associated with it I can give you proper query.

0 Karma

mayurr98
Super Champion

You need to edit these query according to naming of the field names in your data.

0 Karma

JgTheGreat
Engager

Query in original question - hope that this helps!

0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...