Splunk 7.3.3 仪表盘构建求助:求各类安全事件与系统状态监控的查询语句
我刚好在Splunk 7.3.3环境中处理过类似的Windows运维安全与性能监控需求,下面是针对你提到的各个场景整理的实用查询语句,你可以直接复用或者根据自己的环境调整过滤条件:
1. 管理员登录失败
针对Windows系统,登录失败对应EventCode=4625,结合管理员账户/组过滤:
index=windows EventCode=4625 | eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") | where is_admin="是" | stats count BY TargetUserName, IpAddress, _time
说明:可以根据实际管理员账户列表扩展Account_Name范围,也可以通过Group_Name匹配管理员组的账户
2. 非工作时段管理员登录失败(支持全时段筛选)
先定义工作时段(示例为周一至周五9:00-18:00),再过滤非工作时段的失败事件:
index=windows EventCode=4625 | eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") | where is_admin="是" | eval day_of_week=strftime(_time, "%A") | eval hour_of_day=strftime(_time, "%H") | eval is_work_hours=if((day_of_week IN ("Monday", "Tuesday", "Wednesday", "Thursday", "Friday") AND hour_of_day>=9 AND hour_of_day<18), "工作时段", "非工作时段") | where is_work_hours="非工作时段" | stats count BY TargetUserName, IpAddress, _time
说明:可修改day_of_week和hour_of_day的判断逻辑适配你的工作时段,仪表盘添加时间范围控件即可支持全时段筛选
3. 来自OCONUS IP的管理员登录
用Splunk内置的iplocation命令识别地理位置,筛选境外IP的管理员登录:
index=windows EventCode=4624 | eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") | where is_admin="是" | iplocation IpAddress | where Country!="United States" // 根据需求调整排除的国家 | stats count BY TargetUserName, IpAddress, Country, _time
说明:如果有内部维护的OCONUS IP列表,用lookup命令关联会比iplocation更精准
4. 账户锁定状态下的管理员登录尝试
关联账户锁定事件(EventCode=4740)和登录失败事件,筛选同时出现的管理员账户:
index=windows (EventCode=4625 OR EventCode=4740) | eval admin_account=if(Account_Name IN ("Administrator", "你的其他管理员账户"), Account_Name, null()) | where isnotnull(admin_account) | stats values(EventCode) as event_types, count BY admin_account, _time | where mvcount(event_types)=2 // 筛选既有锁定又有登录失败的账户
5. 尝试使用过期密码登录
Windows中使用过期密码登录失败的状态码为0xc000006f,结合该条件筛选:
index=windows EventCode=4625 Status=0xc000006f | eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") | where is_admin="是" | stats count BY TargetUserName, IpAddress, _time
6. 绕过登录或未强制PKI
如果环境强制PKI登录,未使用PKI的登录会对应特定的认证包名称,以此筛选异常事件:
index=windows EventCode=4624 | eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") | where is_admin="是" | where AuthenticationPackageName!="Kerberos" // 替换为你的PKI认证包名称 | stats count BY TargetUserName, IpAddress, AuthenticationPackageName, _time
说明:需确认环境中PKI登录对应的AuthenticationPackageName值,可能是Negotiate或其他自定义值
7. 多因素认证/修改认证规则的登录失败尝试
- MFA登录失败:对应EventCode=4625及MFA专属错误码(示例为
0xc000006a) - 修改认证规则:对应EventCode=4719
// MFA登录失败查询 index=windows EventCode=4625 SubStatus=0xc000006a | eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") | where is_admin="是" | stats count BY TargetUserName, IpAddress, _time // 认证规则修改查询 index=windows EventCode=4719 | stats count BY SubjectUserName, _time
说明:不同MFA方案的错误码可能不同,需根据实际日志调整SubStatus值
8. 系统超时
监控远程桌面会话超时事件(EventCode=4778):
index=windows EventCode=4778 | eval is_admin=if(Account_Name IN ("Administrator", "你的其他管理员账户"), "是", "否") | where is_admin="是" | stats count BY TargetUserName, IpAddress, _time
9. 系统内存峰值
通过perfmon数据源监控内存使用率峰值:
index=perfmon object="Memory" counter="% Committed Bytes In Use" | stats max(Value) as peak_memory_usage BY host, _time span=1h | where peak_memory_usage>90 // 可调整阈值
说明:需确保Splunk已采集Windows的perfmon性能数据
10. 系统网络流量峰值
同样使用perfmon数据监控网卡流量峰值:
index=perfmon object="Network Interface" counter="Bytes Total/sec" | stats max(Value) as peak_network_traffic BY host, _time span=1h | where peak_network_traffic>100000000 // 调整阈值(单位:字节/秒)
11. 系统错误
监控Windows系统日志中的错误级别事件:
index=windows source="WinEventLog:System" EventType="Error" | stats count BY EventCode, Message, host, _time
另外,你提到的管理员账户创建/添加查询可以优化得更精准:
index=windows source="WinEventLog:Security" (EventCode=4720) OR (EventCode=4732 AND Group_Name="Administrators") | stats count BY TargetUserName, SubjectUserName, _time
内容的提问来源于stack exchange,提问作者weteamsteve

