Quantcast
Viewing all articles
Browse latest Browse all 47296

I'm looking for a query to search for users logging in remotely via either Remote desktop, through a VM in ESXI or with SSH terminal into the domain that our Splunk server is in

We had a user log in remotely either with ESXI with a VM, with Remote Desktop or with the command prompt using SSH. Our Splunk server is on a domain and we are trying to determine who logged in and made changes. I have searched the forum and cannot find a definite answer in the community. I'm fairly new to Splunk with writing queries and all so appreciate any help and/or advice anyone can give. Thanks,

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>