Password changes in a Windows environment by user account WinEventLog:Security Go Splunk 3 1 Password changes in a Windows environment by user account. sourcetype="WinEventLog:Security" (EventCode=628 OR EventCode=627 OR EventCode=4723 OR EventCode=4724) | chart count by user 1 sourcetype="WinEventLog:Security" (EventCode=628 OR EventCode=627 OR EventCode=4723 OR EventCode=4724) | chart count by user Continue Reading →