Splunk Search

domain accounts search csv

japonter
Explorer

Hi,

i have been looking but cant seem to make much sense of it all. im new to splunk.

im trying to create a search and alert from a csv file, the csv fiel contains Domain Admin account and i wanted to creat a search for a numbers of eventid on those domain admin accounts.

index=win sourcetype=wineventlog EventCode=*the events im looking for* | inputlookup file.csv

 

but cant seem to make it work.

 

any help would be great

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Do the field names from your search match the field names in your csv - you should have one that matches to be able to lookup in the csv

0 Karma

japonter
Explorer

the usernames in the csv are name from a AD group called domain admin, if i search for them one by one i find there with the events id, but theres around 70 names and i want to use the csv file to make it easier to search for events with specific eventid with those names.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share some events with the fields you want to match on and the same from the lookup file?

0 Karma

japonter
Explorer

this is one of the events i want to search.

the csv file are just domain admin user names. one column one row of just names.

NOTE: I come from using QRadar for over 5 years, to using splunk for the first time, and i am finding it difficult to transition from one platform to another.

07/06/2021 10:11:23 AM

LogName=Security EventCode=4724

EventType=0 ComputerName=Localhost.local SourceName=Microsoft Windows security auditing. Type=Information RecordNumber=13407054485 Keywords=Audit Success TaskCategory=User Account Management OpCode=Info Message=An attempt was made to reset an account's password.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...