• Search
  • Dashboards
  • Browse
    • Sourcetype

      • _audit
      • _internal
      • access_combined
      • apache
      • audittrail
      • citrix:netscaler:syslog
      • Cron
      • crowdstrike
      • Dashboards
      • datamodels
      • DBConnect
      • Enterprise Security
      • eval
      • F5
      • Fun Stuff & Helpful Hints
      • Hack
      • Hygiene
      • IIS
      • Juniper
      • Linux Performance
      • linux_secure
      • Malware
      • Monitoring
      • Networking
      • opensense
      • opsec
      • osx_secure
      • Perfmon:Available Memory
      • Perfmon:CPU Load
      • Perfmon:Free Disk Space
      • Perfmon:Network Interface
      • postfix_syslog
      • Qualys
      • REST
      • RFQ – Request For Query
      • splunkd
      • Tenable
      • Uncategorized
      • Unix:Uptime
      • WinEventLog:Application
      • WinEventLog:Security
      • WinEventLog:System
      • WinRegistry
      • WMI:Uptime
    • Tags

      6.1.2 admin apache audit audittrail authentication Cisco Diagnostics failed logon Firewall IIS index indexes internal license License usage Linux linux audit Login Logon malware Network Perfmon Performance qualys REST Security sourcetype splunk splunkd splunk on splunk Tenable Tenable Security Center troubleshoot troubleshooting tstats Universal Forwarder users Vulnerabilities Web Traffic Windows Windows Audit Windows Security _audit _internal
  • Post New Query
  • Our Blog
  • Splunk Jobs
  • Search
  • Dashboards
  • Browse
    • Sourcetype

      • _audit
      • _internal
      • access_combined
      • apache
      • audittrail
      • citrix:netscaler:syslog
      • Cron
      • crowdstrike
      • Dashboards
      • datamodels
      • DBConnect
      • Enterprise Security
      • eval
      • F5
      • Fun Stuff & Helpful Hints
      • Hack
      • Hygiene
      • IIS
      • Juniper
      • Linux Performance
      • linux_secure
      • Malware
      • Monitoring
      • Networking
      • opensense
      • opsec
      • osx_secure
      • Perfmon:Available Memory
      • Perfmon:CPU Load
      • Perfmon:Free Disk Space
      • Perfmon:Network Interface
      • postfix_syslog
      • Qualys
      • REST
      • RFQ – Request For Query
      • splunkd
      • Tenable
      • Uncategorized
      • Unix:Uptime
      • WinEventLog:Application
      • WinEventLog:Security
      • WinEventLog:System
      • WinRegistry
      • WMI:Uptime
    • Tags

      6.1.2 admin apache audit audittrail authentication Cisco Diagnostics failed logon Firewall IIS index indexes internal license License usage Linux linux audit Login Logon malware Network Perfmon Performance qualys REST Security sourcetype splunk splunkd splunk on splunk Tenable Tenable Security Center troubleshoot troubleshooting tstats Universal Forwarder users Vulnerabilities Web Traffic Windows Windows Audit Windows Security _audit _internal
  • Post New Query
  • Our Blog
  • Splunk Jobs

Members

Profile picture of CattyWampus

CattyWampus

@cattywampus Active 9 years, 5 months ago
  • Activity
  • Profile
  • Posts
  • Personal
  • Mentions
  • Favorites
  • Profile picture of CattyWampus
    4 years, 11 months ago

    CattyWampus commented on the post, Weekend User Activity

    In reply to: SplunkNinja wrote a new post Run the following (modify user field as needed) to show weekend activity: sourcetype="WinEventLog:Security" (date_wday=saturday OR date_wday=sunday) | stats count by Account_Name, date_wday View

    yes you can specify by: Account_Name=”user_name_here”

  • Profile picture of CattyWampus
    9 years, 5 months ago

    CattyWampus wrote a new post

    Qualys Hosts not Scanned in 30 days+The following Splunk Search (query) is for Qualys and will show hosts that have not been scanned in 30 days or more. This query assumes that your index is […]

  • Profile picture of CattyWampus
    9 years, 5 months ago

    CattyWampus wrote a new post

    Qualys 30 Day trending of Re-Opened VulnerabilitiesThe following Splunk Search (query) is for Qualys and will show a trending over 30 days for re-opened vulnerabilities. This query assumes that your index is […]

  • Profile picture of CattyWampus
    9 years, 5 months ago

    CattyWampus wrote a new post

    Qualys Top 10 Vulnerabilities by SeverityThe following Splunk Search (query) is for Qualys and will show the top 10 vulnerabilities by severity as well as a Count of […]

  • Profile picture of CattyWampus
    9 years, 5 months ago

    CattyWampus wrote a new post

    Qualys Active OS Vuln CountThe following Splunk Search (query) is for Qualys and will show vulnerability count for Windows Hosts. This query assumes that your index is defined as […]

  • Profile picture of CattyWampus
    10 years, 7 months ago

    CattyWampus wrote a new post

    This will return a table of users who conducted searches, the total time it took for searches to complete, a count of said searches, and the last time a search was conducted.

    *NOTE* You will need to modify […]

  • Profile picture of CattyWampus
    10 years, 7 months ago

    CattyWampus wrote a new post

    This will return a list of users who attempted to login to the splunk searchhead. It will list both successful attempts and failed attempts.

    index=_audit tag=authentication | stats count by user, info | sort – info

    • Profile picture of cm1805mason
      cm1805mason replied 2 years, 8 months ago

      index=_audit tag=authentication | dedup user | stats count by user, info timestamp | sort – info

  • Profile picture of CattyWampus
    10 years, 7 months ago

    CattyWampus wrote a new post

    This query will search the internal audit sourcetype of splunk and report on any user modification attempts, both success and fail.
    index=_audit sourcetype=audittrail action=edit_user | eval Date=strftime(_time, […]

  • Profile picture of CattyWampus
    10 years, 7 months ago

    CattyWampus became a registered member

  • Home
  • Log In
  • Register
  • About GoSplunk
  • GoSplunk FAQs
  • Contact the GoSplunk Team
  • Splunk Website
  • Splunk Documentation
  • Splunk Answers

GoSplunk is not affiliated with Splunk Inc. in any way.

© 2019 GoSplunk
  • Privacy Policy
  • Terms and Conditions
  • Forgot Password?
sponsored