# Service accounts tracker for Kibana

**URL:** <https://discuss.elastic.co/t/service-accounts-tracker-for-kibana/146720>\
**Category:** Kibana\
**Created:** [August 30, 2018, 2:05pm UTC](https://discuss.elastic.co/t/service-accounts-tracker-for-kibana/146720 "2018-08-30T14:05:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrew\_Vdovin](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@Andrew\_Vdovin](https://discuss.elastic.co/u/Andrew_Vdovin)\
**Post date:** [August 30, 2018, 2:05pm UTC](https://discuss.elastic.co/t/service-accounts-tracker-for-kibana/146720/1 "2018-08-30T14:05:21Z")

</div>

Service accounts is a necessary evil in every company of any size. Service accounts mostly unpersonalized, shared, privileged, with non expired passwords. This is a big challenge for any compliance. You can’t just prohibit service accounts operation, disable them or ignore this problem. And first step on the way of the situation improvement is to start tracking of Service accounts usage. You already have all necessary information for that in your SIEM. You just need to download and install “Service Accounts Tracker” Use Case that processes this information and visualize it in simple and actionable way.  
Here how it looks like -

 ![dash1-7arNV](https://us1.discourse-cdn.com/elastic/original/3X/4/3/43656bb7b24686ed7ca07260db859cbfa56281f1.png)  
 ![dash2-tEanM](https://us1.discourse-cdn.com/elastic/original/3X/8/3/83dd548ba9eea49b329fa02a645ac12839863e2c.png)

Link for more info - [https://my.socprime.com/en/integrations/service-accounts-tracker-kibana](https://my.socprime.com/en/integrations/service-accounts-tracker-kibana)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 30, 2018, 8:07pm UTC](https://discuss.elastic.co/t/service-accounts-tracker-for-kibana/146720/2 "2018-08-30T20:07:51Z")

</div>

It's not entirely clear what this is about.

Is it a plugin? It is only for Kibana 5.X? Is it free? What does it integrate with?

---

<div class="post-metadata">

**Author:** ![Andrew\_Vdovin](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@Andrew\_Vdovin](https://discuss.elastic.co/u/Andrew_Vdovin)\
**Post date:** [August 31, 2018, 6:59am UTC](https://discuss.elastic.co/t/service-accounts-tracker-for-kibana/146720/3 "2018-08-31T06:59:22Z")

</div>

Hi, thanks for your questions.

1. Yes, it is a plugin.
2. For Kibana 6.1 or higher.
3. You can download it for free after the registration at [https://tdm.socprime.com](https://tdm.socprime.com)
4. It works with any events which contain information about source or destination user names in CEF format.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2018, 7:11am UTC](https://discuss.elastic.co/t/service-accounts-tracker-for-kibana/146720/4 "2018-09-28T07:11:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
