Splunk Search

How to create a table that shows multiple failed logins on the same workstation by different usernames?

bakalon
Explorer

Hello,
So I'm looking to a use case where I have to create a table that shows multiple failed logins on the same workstation by different usernames.

Here's what I have so far:

index=windows* sourcetype=WinEventLog:Security EventCode=4625 | eval AccountName=mvindex(Account_Name, 1) | | stats  values(AccountName) by Workstation_Name

That shows all accounts that failed to log in. I want the result where there are multiple failed accounts on the same workstation. So something like ....| where AccountName > 1.

Please let me know if this makes sense. Thanks!

0 Karma
1 Solution

somesoni2
Revered Legend

Try like this

index=windows* sourcetype=WinEventLog:Security EventCode=4625 | eval AccountName=mvindex(Account_Name, 1) |  stats  values(AccountName) as Accounts by Workstation_Name | where mvcount(Accounts)>1

View solution in original post

somesoni2
Revered Legend

Try like this

index=windows* sourcetype=WinEventLog:Security EventCode=4625 | eval AccountName=mvindex(Account_Name, 1) |  stats  values(AccountName) as Accounts by Workstation_Name | where mvcount(Accounts)>1

bakalon
Explorer

Dude!!! Thank you very much. I was not aware of the mvcount expression. This worked like a charm. Cheers!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...