Splunk search for Unsuccessful OSX logins

Copy
sourcetype=osx_secure | rex field=_raw "authinternal\sfaile\sto\sauthenticate\suser\s(?<user>\S+)" | stats count by user, host | sort - count
This search will show unsuccessful login attempts to a Mac OSX system
0 comments

Category:

Mac


Tags:

mac osx authentication

Search Commands:

Sign in or Register to submit a comment