Failed Logon Attempts – Windows

The following Splunk query will show a timechart of failed logon attempts per host:

The following Splunk query will show a detailed table of failed logon attempts per host and user with 5 minute chunks/blocks of time, as well as show a sparkline (mini timechart) within the table itself.

#Admin Notes – This query has replaced the original query on GoSplunk due to changes in the way Splunk displays windows data as well as eliminated pre-Windows 2008 EventCodes.

Share This:

Leave A Comment?