Linux User Account Activity Create User (via Splunk): useradd, plain

info Nessus Network Monitor Plugin ID 710012

Synopsis

SIEM Pull Service has detected via Splunk query that, on this Linux system, a user account was created.

Description

SIEM Pull Service has detected via Splunk query that, on this Linux system, a user account was created. The query used was (sourcetype=linux_audit OR sourcetype=linux_secure) AND (new* OR ADD) AND (user OR USER)

Solution

N/A

Plugin Details

Severity: Info

ID: 710012

Family: Policy

Published: 8/20/2004

Updated: 5/18/2018