Synopsis
SIEM Pull Service has detected via Splunk query that, on this Linux system, a user changed password.
Description
SIEM Pull Service has detected via Splunk query that, on this Linux system, a user changed password. The query used was (sourcetype=linux_audit OR sourcetype=linux_secure OR type=USER_CHAUTHTOK) AND (updat* OR chang*) AND (password)