You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需AI/ML:Splunk查询7天内罕见用户主机登录事件

解决方案:无需机器学习实现特定主机罕见登录用户查询

核心思路

要找出过去7天内从未在任何受监控主机登录,但突然在指定主机登录的用户,核心是两步精准筛选:

  1. 仅在目标主机有登录记录的用户
  2. 该用户在过去7天前无任何登录记录

完全可以通过Splunk的基础统计、子查询、集合运算命令实现,无需依赖机器学习。

修正后的查询语句

假设目标主机为TARGET_HOST,以下是两种可靠的查询方案:

方案1:统计主机登录数+验证历史登录

index="main" EventCode=4624 earliest=-7d latest=now
| stats dc(host) as host_count, earliest(_time) as first_login_time by user
| where host_count=1  // 筛选仅在一台主机登录的用户
| join type=inner user [
    // 仅保留在目标主机登录的用户
    index="main" EventCode=4624 earliest=-7d latest=now host=TARGET_HOST
    | stats values(host) as login_host by user
]
// 验证用户在过去7天前无登录记录(可调整时间范围,比如查前30天)
| join type=left user [
    index="main" EventCode=4624 earliest=-30d latest=-7d+1s
    | stats count as prior_login_count by user
]
| where isnull(prior_login_count) OR prior_login_count=0
| eval first_login=strftime(first_login_time, "%Y-%m-%d %H:%M:%S")
| table user login_host first_login

方案2:集合运算筛选目标用户

// 用集合差运算,找出仅在目标主机登录的用户
| set diff [
    index="main" EventCode=4624 earliest=-7d latest=now host=TARGET_HOST
    | dedup user
    | fields user
] [
    index="main" EventCode=4624 earliest=-7d latest=now host!=TARGET_HOST
    | dedup user
    | fields user
]
// 验证该用户历史无登录记录
| join type=left user [
    index="main" EventCode=4624 earliest=-30d latest=-7d+1s
    | stats count as prior_logins by user
]
| where isnull(prior_logins) OR prior_logins=0
| table user

你之前查询的问题

  • rare命令仅用于识别低频出现的字段值,无法精准匹配「仅在特定主机登录+历史无登录」的业务逻辑
  • 查询中account字段大概率不是你的数据字段(应使用user),dc(hostname)应为dc(host),且未区分目标主机与其他主机的登录情况,导致结果不符合预期

内容的提问来源于stack exchange,提问作者doofyHi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 06:35:29