Getting Data In

Why are users being seen as services accounts at logon?

Heritic88
Explorer

I am using a virtual server and all users are being seen as service accounts.  Which is causing my logon and admin account searches to show some very high numbers (authentications are showing as logons).  Is there a way to get the system to ignore the actual service accounts that are running that are not users where as both are being seen as a logon type 3 (Network)?

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you filtering out logons where the account name ends with "$"?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Heritic88
Explorer

Index=wineventlog Eventcode= 4624 user!=*$ user!=system | stats count 

updated

 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...