You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk 7.3.3 仪表盘构建求助:求各类安全事件与系统状态监控的查询语句

Splunk 7.3.3 Windows运维监控查询语句分享

我刚好在Splunk 7.3.3环境中处理过类似的Windows运维安全与性能监控需求,下面是针对你提到的各个场景整理的实用查询语句,你可以直接复用或者根据自己的环境调整过滤条件:

1. 管理员登录失败

针对Windows系统,登录失败对应EventCode=4625,结合管理员账户/组过滤:

index=windows EventCode=4625 
| eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") 
| where is_admin="是" 
| stats count BY TargetUserName, IpAddress, _time

说明:可以根据实际管理员账户列表扩展Account_Name范围,也可以通过Group_Name匹配管理员组的账户

2. 非工作时段管理员登录失败(支持全时段筛选)

先定义工作时段(示例为周一至周五9:00-18:00),再过滤非工作时段的失败事件:

index=windows EventCode=4625 
| eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") 
| where is_admin="是"
| eval day_of_week=strftime(_time, "%A")
| eval hour_of_day=strftime(_time, "%H")
| eval is_work_hours=if((day_of_week IN ("Monday", "Tuesday", "Wednesday", "Thursday", "Friday") AND hour_of_day>=9 AND hour_of_day<18), "工作时段", "非工作时段")
| where is_work_hours="非工作时段"
| stats count BY TargetUserName, IpAddress, _time

说明:可修改day_of_week和hour_of_day的判断逻辑适配你的工作时段,仪表盘添加时间范围控件即可支持全时段筛选

3. 来自OCONUS IP的管理员登录

用Splunk内置的iplocation命令识别地理位置,筛选境外IP的管理员登录:

index=windows EventCode=4624 
| eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") 
| where is_admin="是"
| iplocation IpAddress
| where Country!="United States"  // 根据需求调整排除的国家
| stats count BY TargetUserName, IpAddress, Country, _time

说明:如果有内部维护的OCONUS IP列表,用lookup命令关联会比iplocation更精准

4. 账户锁定状态下的管理员登录尝试

关联账户锁定事件(EventCode=4740)和登录失败事件,筛选同时出现的管理员账户:

index=windows (EventCode=4625 OR EventCode=4740)
| eval admin_account=if(Account_Name IN ("Administrator", "你的其他管理员账户"), Account_Name, null())
| where isnotnull(admin_account)
| stats values(EventCode) as event_types, count BY admin_account, _time
| where mvcount(event_types)=2  // 筛选既有锁定又有登录失败的账户

5. 尝试使用过期密码登录

Windows中使用过期密码登录失败的状态码为0xc000006f,结合该条件筛选:

index=windows EventCode=4625 Status=0xc000006f
| eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") 
| where is_admin="是"
| stats count BY TargetUserName, IpAddress, _time

6. 绕过登录或未强制PKI

如果环境强制PKI登录,未使用PKI的登录会对应特定的认证包名称,以此筛选异常事件:

index=windows EventCode=4624 
| eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") 
| where is_admin="是"
| where AuthenticationPackageName!="Kerberos"  // 替换为你的PKI认证包名称
| stats count BY TargetUserName, IpAddress, AuthenticationPackageName, _time

说明:需确认环境中PKI登录对应的AuthenticationPackageName值,可能是Negotiate或其他自定义值

7. 多因素认证/修改认证规则的登录失败尝试

  • MFA登录失败:对应EventCode=4625及MFA专属错误码(示例为0xc000006a)
  • 修改认证规则:对应EventCode=4719
// MFA登录失败查询
index=windows EventCode=4625 SubStatus=0xc000006a
| eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") 
| where is_admin="是"
| stats count BY TargetUserName, IpAddress, _time

// 认证规则修改查询
index=windows EventCode=4719
| stats count BY SubjectUserName, _time

说明:不同MFA方案的错误码可能不同,需根据实际日志调整SubStatus值

8. 系统超时

监控远程桌面会话超时事件(EventCode=4778):

index=windows EventCode=4778
| eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") 
| where is_admin="是"
| stats count BY TargetUserName, IpAddress, _time

9. 系统内存峰值

通过perfmon数据源监控内存使用率峰值:

index=perfmon object="Memory" counter="% Committed Bytes In Use"
| stats max(Value) as peak_memory_usage BY host, _time span=1h
| where peak_memory_usage>90  // 可调整阈值

说明:需确保Splunk已采集Windows的perfmon性能数据

10. 系统网络流量峰值

同样使用perfmon数据监控网卡流量峰值:

index=perfmon object="Network Interface" counter="Bytes Total/sec"
| stats max(Value) as peak_network_traffic BY host, _time span=1h
| where peak_network_traffic>100000000  // 调整阈值(单位:字节/秒)

11. 系统错误

监控Windows系统日志中的错误级别事件:

index=windows source="WinEventLog:System" EventType="Error"
| stats count BY EventCode, Message, host, _time

另外,你提到的管理员账户创建/添加查询可以优化得更精准:

index=windows source="WinEventLog:Security" 
(EventCode=4720) OR (EventCode=4732 AND Group_Name="Administrators")
| stats count BY TargetUserName, SubjectUserName, _time

内容的提问来源于stack exchange,提问作者weteamsteve

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 20:27:49