Splunk Search

Usernames Failed to Login against an IP Address | which other IP Addresses has that Username Failed to login against?

JgTheGreat
Engager

Hello,

I'm looking for a query, which looks for successful [ or unsuccessful ] brute force attempts, and then to take the Username that was [ or unsuccessfully/successfully logged in and then automatically return which other (if any) IP's that account was logged into.

Virtual beers and a high five on offer here 😄

KJG

Tags (1)
0 Karma

mayurr98
Super Champion
index=your_index status=succes OR status=unsuccessful | stats values(srcip) by users status

If you give me sample event and field names associated with it I can give you proper query.

0 Karma

mayurr98
Super Champion

You need to edit these query according to naming of the field names in your data.

0 Karma

JgTheGreat
Engager

Query in original question - hope that this helps!

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...