Merge pull request #2239 from splunk/user_enum_fix

Updated macro to not rely on field extraction
This commit is contained in:
Lou Stella
2022-06-06 15:30:20 -05:00
committed by GitHub
+1 -1
View File
@@ -1,4 +1,4 @@
definition: index=_audit action="login attempt" info="failed"
definition: index=_audit "action=login attempt" "info=failed"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
name: splunkd_failed_auths