Password changes in a Windows environment by user account WinEventLog:Security Go Splunk Vote Up +4 Vote Down -1You already voted! Password changes in a Windows environment by user account. sourcetype="WinEventLog:Security" (EventCode=628 OR EventCode=627 OR EventCode=4723 OR EventCode=4724) | chart count by user Share This: Tagged: 6.1.2PasswordPassword ChangesSecurityWindowsWindows Security