Password changes in a Windows environment by user account WinEventLog:Security Go Splunk Vote Up +4 Vote Down -1You already voted! Password changes in a Windows environment by user account. sourcetype=”WinEventLog:Security” (EventCode=628 OR EventCode=627 OR EventCode=4723 OR EventCode=4724) | chart count by user Continue Reading →