Splunk Search

domain accounts search csv

japonter
Explorer

Hi,

i have been looking but cant seem to make much sense of it all. im new to splunk.

im trying to create a search and alert from a csv file, the csv fiel contains Domain Admin account and i wanted to creat a search for a numbers of eventid on those domain admin accounts.

index=win sourcetype=wineventlog EventCode=*the events im looking for* | inputlookup file.csv

 

but cant seem to make it work.

 

any help would be great

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Do the field names from your search match the field names in your csv - you should have one that matches to be able to lookup in the csv

0 Karma

japonter
Explorer

the usernames in the csv are name from a AD group called domain admin, if i search for them one by one i find there with the events id, but theres around 70 names and i want to use the csv file to make it easier to search for events with specific eventid with those names.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share some events with the fields you want to match on and the same from the lookup file?

0 Karma

japonter
Explorer

this is one of the events i want to search.

the csv file are just domain admin user names. one column one row of just names.

NOTE: I come from using QRadar for over 5 years, to using splunk for the first time, and i am finding it difficult to transition from one platform to another.

07/06/2021 10:11:23 AM

LogName=Security EventCode=4724

EventType=0 ComputerName=Localhost.local SourceName=Microsoft Windows security auditing. Type=Information RecordNumber=13407054485 Keywords=Audit Success TaskCategory=User Account Management OpCode=Info Message=An attempt was made to reset an account's password.

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...