investigating-splunk-login-activity
Investigates login and authentication activity on Splunk instances using the _audit index. Use when analyzing user access patterns, session behavior, authentication anomalies, login failures, token usage, API access patterns, or any security-related access questions on a Splunk deployment.
Changelog: Source: GitHub https://github.com/jagalliers/opsblaze
Loading comments...