Linux User Account Activity Change Password (via Splunk): usermod, plain

info Nessus Network Monitor Plugin ID 710015

Synopsis

SIEM Pull Service has detected via Splunk query that, on this Linux system, a user changed password.

Description

SIEM Pull Service has detected via Splunk query that, on this Linux system, a user changed password. The query used was (sourcetype=linux_audit OR sourcetype=linux_secure OR type=USER_CHAUTHTOK) AND (updat* OR chang*) AND (password)

Solution

N/A

Plugin Details

Severity: Info

ID: 710015

Family: Policy

Published: 8/20/2004

Updated: 5/18/2018