Alerting

We try to filter login Alert to other team via email using "NOT" whoever login to server

Mplunk2work
Observer

index=12345_ati_pia NOT Logon_Type!=10 NOT Account_Name=abc* NOT Account_Name=te* (EventCode=5421 Logon_Type=10 NOT Target_Server_Name=localhost) OR (EventCode=5421 NOT Account_Name=$) NOT Account_Name=DNA NOT Account_Name=te* NOT Account_Name=SYSTEM NOT Account_Name=BladeLogicCAMR NOT Account_Name=abckk1 NOT Account_Name=IOWADBQ NOT Account_Name=cored1 NOT Account_Name=ANON* NOT Account_Name=dmvcars

Tags (1)
0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

Hi @mplunk2work. In general, your question has a greater chance of being answered by experts in the Answers community when when you provide as much information and context as possible. Thanks!

0 Karma

skoelpin
SplunkTrust
SplunkTrust

What's your question?

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...