Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Searching logs from 2 domain controllers to find locked out users, why do we sometimes get a log from both DCs when a user gets locked out once?

$
0
0
This isn't so much of a Splunk question. More of an Active Directory question, but I'm trying to search through our `source="WMI:WinEventLog:Security"` logs from our domain controllers to find locked out users. Most of the time, when a user locks themselves out, we see a log from 1 of our 2 domain controllers. SOMETIMES when a user gets locked out, we get a log from BOTH domain controllers. And they just got locked out once. I'm wondering if anyone has seen this before and knows WHY this happens? Thanks a bunch

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>