Splunk Search

Search to find unauthorized host(s) last login date

cjsweeney1
Explorer

Hi looking for a search to find any unauthorized systems that are sitting on a network and the last login date.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To find unauthorized systems you'll first need a list of the authorized systems, perhaps in a lookup file. Then search to find ALL systems on your network and compare that list to the authorized list. The difference is the unauthorized systems.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cjsweeney1
Explorer

Hey Rich,

You know a search string to find a particular hosts last ip "pull" is... I'm wondering if the last time it had a DHCP timestamp assigned is all I will be able to get.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't know that.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cjsweeney1
Explorer

Hmmm.... could work. Could that lookup file be automatically updated? I was hoping enterprise security would have a report like this built-in.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it's possible to automatically update the lookup file.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...