Synopsis
SIEM Pull Service has detected via Splunk query that, on this Linux system, a user account was created.
Description
SIEM Pull Service has detected via Splunk query that, on this Linux system, a user account was created. The query used was (sourcetype=linux_audit OR sourcetype=linux_secure) AND (new* OR ADD) AND (user OR USER)