Hello sekar, Good day!!! Thanks for your reply. Below are my comments: 1. do you use Splunk_TA_nix or not - we are not using Splunk_TA_nix 2. do you want to monitor for the root user or any user?.. because, linux users generally login with their user access and then do the sudo to become root., right.. so you might want to monitor user login failures, right.. or sudo commands you want to monitor.. - ---That's correct we can't directly access sudo user, but i'm looking is for sudo/root password reset attempts after multiple user login failures. Regards, Kspriya
... View more