AD: Splunk AD Account Lockout Dashboard Guide (ETS Internal)

Summary 

https://unhsystem.splunkcloud.com/en-US/app/search/lockout_events_ad 

This dashboard comprises two different reporting sections: 

  • Lockouts with Source and DC (Domain Controller) 
  • Lockout Stats 

The default timeframe to search is 24 hours. This can be adjusted using the "Global Time Range" selector. It is recommended not to look for more than 2-3 days of history, as this can result in slow execution, when Splunk is busy.  

Data is sent from AD to Splunk almost instantly; however, the rate at which it is indexed for searchability is generally 20-30 minutes behind the current time. Searching for smaller increments of time relative to the present will yield a less accurate result

Note: Starting in June 2026, all Splunk access is through your ADM_ account

 

Dashboard Descriptions 

Lockouts with Source and DC 

This dashboard table shows locked out accounts with the proximate source of the account lockout. It will display only the UNIQUE LockoutSources for the account. 

Lockouts with Source and DC will show the following information: 

  • Further Readings below for links to converters from UTC to Eastern Time.
  • LockoutSource — the system that requested authorization from AD at LockoutTime. 
  • Account Locked Out — the account that was locked out. 
  • Domain Controller — the domain controller that processed the lockout trigger. 

 

Features: 

In the header of this Dashboard block is a “User Selection” menu that facilitates scoping of the displayed data to a particular user or subset of users.  

Mousing over the lower portion of this dashboard section will reveal a popup menu that provides access to standard Splunk options, including the ability to download the data as a CSV. 

 

Lockout Stats 

This dashboard table shows user accounts that have been locked out, with a total COUNT of lockout events for the timeframe specified in the "Global Time Range." Additionally, it includes a display of the affiliations and roles held by that user. Similar to the "Lockouts with Source and DC" Panel, it includes a username based search. 

Lockout Stats will show the following information: 

  • Target_User_Name — the username of the locked-out account. 
  • Count — The number of times this account has been locked out in the time period specified in the “Global Time Range.” 
  • Affiliation — the aggregation of all affiliations granting account entitlement to a Primary user account. 
  • Type — the user’s highest functional classification, which may be used to determine or confirm processing requirements. 

 

Features: 

Mousing over the lower portion of this dashboard section will reveal a popup menu that provides access to standard Splunk options, including the ability to download the data as a CSV. 

 

Changes/Fixes

Completed: 

  1. 02/19/2024 – Updated “Lockouts with Source and DC” table to use a numeric date  format, updated header to specify that times are in UTC. Requested by Katie Ellis. 

  1. 04/23/2024 – Added Search to “Lockout Stats Panel”. Added 30 Day lockout total history. 

  2. 04/23/2024 – 

    1. Changed the word "usnhPersonMajorAffiliation" to "Affiliation" under the Lockout Stats section
    2. Changed the word "usnhPersonPrimaryUserType" to "Type" under the Lockout Stats section
    3. Added "Similar to the "Lockouts with Source and DC" Panel, it includes a username based search. " to the Lockout Stats section
       
  3. 06/2026 - All Splunk access is through ADM_ accounts.  Regular account access will be removed in July 2026.
     
  4.  

 

Further Readings

Splunk Lockout Events (AD) Dashboard  - https://unhsystem.splunkcloud.com/en-US/app/search/lockout_events_ad 

UTC to EST Time Converter  

UTC to EDT Time Converter  

Tim Clark's original version of this document, the Splunk AD Account Lockout Dashboard Guide  - from which this article derives.

 

Need additional help?

If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.