-
6 years ago
hokiefans commented on the post, Failed Attempt to Login to a Disabled Account
In reply to: SplunkNinja wrote a new post This Splunk Search Query will indicate any user who attempted to login to a disabled account. (Tested only on Windows 7 / Server 2008 and newer Windows […] ViewNeed to change the rename section to read, starting with the pipe:
| rename facct as “Target Account” host as “Host” Keywords as “Status” count as “Count” -
6 years ago
hokiefans became a registered member
-
6 years ago
hokiefans became a registered member