splunkWindowsv1.0
Windows Remote Logon Activity Detection
Detects successful Windows remote logon activity using Event ID 4624 and Logon Type 10, which indicates Remote Interactive Logon commonly associated with RDP. The query helps security analysts monitor remote access by displaying the timestamp, username, source IP address, and logon type for investigation and threat detection.
By Bhanu Prakash Battula · Updated Oct 9, 2026
windows-remote-logon-activity-detection.spl
index=windows event_id=4624| search logon_type=10| table _time, user_name, src_ip, logon_type| sort _time