Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to monitor admin users logged on/authenticated but no session activities for 30mins

$
0
0
I am trying to create an alert to track admin users logged on to windows servers, but not performing any activities even after 30mins of logging in/authentication. index=main (eventtype=logon_activity OR eventtype=wineventlog_security OR eventtype=wineventlog_system) In windows logs, I can use Logon_id to track sessions, but need to find out the age/delta time which is more than 30mins. Any suggestions/thoughts? Thanks in advance.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>