Failed Login to OSX

The following splunk query will return results on users who made unsuccessful attempts to login to an OSX machine:

Continue Reading →

Successful Login to OSX

The following splunk query (with regex) will return a result of users who have successfully authenticated to an OSX machine: *NOTE* Thanks Bob for pointing this out. The regular expression has now been fixed!

Continue Reading →