I am using Splunk (7.3.3) and I am having tremendous difficulties trying to create a dashboard that can show (or 'report') the following information:
- unsuccessful admin logins
- unsuccessful admin logins after duty hours (WINDOWS, ALL HOURS RIGHT NOW)
- admin logins from OCONUS IPs
- admin logon with account locked
- attempts to logon with expired password
- unsuccessful attempts to bypass login or logins not enforcing PKI, multifactor, and or modified authentication enforcement
- system time outs
- system memory spikes
- system network traffic spikes
- system errors
I feel like the majority of these would be common things that people want to use to track these type of issues for their applications and was wondering if anybody would be available to share queries they have used in Splunk 7.3.3.
For simpler stuff such as Windows logons (event code) I am having success using the following query:
index=windows EventCode=4624 | stats count BY TargetUserName - I also pipe in some AND NOTs to prune out bad logs that I am not interested in but took them out for sake of query
For Windows Admin Logins.. I am creating a report that runs query index=* source="*WinEventLog:Security" EventCode=4720 OR (EventCode=4732 Administrators) and add the report to the dashboard.