Splunk Search

domain accounts search csv

japonter
Explorer

Hi,

i have been looking but cant seem to make much sense of it all. im new to splunk.

im trying to create a search and alert from a csv file, the csv fiel contains Domain Admin account and i wanted to creat a search for a numbers of eventid on those domain admin accounts.

index=win sourcetype=wineventlog EventCode=*the events im looking for* | inputlookup file.csv

 

but cant seem to make it work.

 

any help would be great

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Do the field names from your search match the field names in your csv - you should have one that matches to be able to lookup in the csv

0 Karma

japonter
Explorer

the usernames in the csv are name from a AD group called domain admin, if i search for them one by one i find there with the events id, but theres around 70 names and i want to use the csv file to make it easier to search for events with specific eventid with those names.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share some events with the fields you want to match on and the same from the lookup file?

0 Karma

japonter
Explorer

this is one of the events i want to search.

the csv file are just domain admin user names. one column one row of just names.

NOTE: I come from using QRadar for over 5 years, to using splunk for the first time, and i am finding it difficult to transition from one platform to another.

07/06/2021 10:11:23 AM

LogName=Security EventCode=4724

EventType=0 ComputerName=Localhost.local SourceName=Microsoft Windows security auditing. Type=Information RecordNumber=13407054485 Keywords=Audit Success TaskCategory=User Account Management OpCode=Info Message=An attempt was made to reset an account's password.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...