Splunk Search

How to generate a search to find a local account added to admin group within one hour?

abdul_jabbar
New Member

How can I find if a local account/user has been created and then added to the admin/domain admin group within a span of certain time such as 1 hour?
Local user account codes
EventCode=4720 OR EventCode=4721
Admin account codes
EventCode=4732 OR EventCode=4728 OR EventCode=4756
I am not able to structure it right?
Can anybody help

0 Karma

johnpusey
New Member

Have you checked out gosplunk.com? There may be some relevant queries you can use as a starting point (e.g., http://gosplunk.com/?s=Local+user+admin+group&cat=0)

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...