<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: active directory new create and delete user query in Security</title>
    <link>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455796#M10646</link>
    <description>&lt;P&gt;@khanlarloo, did you enable WinEventLog:Security input on your DC as suggested by richgalloway? I also have the Splunk App for Windows Infrastructure installed and I am getting those reports. From Active Directory drop-down, go to Users&amp;gt;&amp;gt;User Reports&amp;gt;&amp;gt;Domain Accounts: New, or Domain Accounts: Deleted. Works!&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2019 12:26:58 GMT</pubDate>
    <dc:creator>dharveynswccd</dc:creator>
    <dc:date>2019-05-17T12:26:58Z</dc:date>
    <item>
      <title>active directory new create and delete user query</title>
      <link>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455793#M10643</link>
      <description>&lt;P&gt;i want to show active directory created user and show deleted users.&lt;BR /&gt;
what is the query for searching in ldapsearch ?&lt;BR /&gt;
 install windows infrastructure app,but when i create user in ad the app doesn't show the created user in users -- &amp;gt;new user &lt;BR /&gt;
and also when i delete user account it doesn't show my deleted user.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 15:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455793#M10643</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2019-05-15T15:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: active directory new create and delete user query</title>
      <link>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455794#M10644</link>
      <description>&lt;P&gt;LDAP search can tell you who is in AD and in which groups, but does not tell you when users are added or removed.  For that, you need Windows event logs.  Install the Splunk Universal Forwarder on your domain controller and enable the WinEventLog:Security input.  This will send events to Splunk each time a user is added or deleted (among many other events).  You can then create searches to find and display created and deleted users.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 13:05:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455794#M10644</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-05-16T13:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: active directory new create and delete user query</title>
      <link>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455795#M10645</link>
      <description>&lt;P&gt;i installed Splunk Universal Forwarder on my domain controller ,but when i create user on ad it doesn't show any log. even in my windows event viewer &lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 07:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455795#M10645</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2019-05-17T07:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: active directory new create and delete user query</title>
      <link>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455796#M10646</link>
      <description>&lt;P&gt;@khanlarloo, did you enable WinEventLog:Security input on your DC as suggested by richgalloway? I also have the Splunk App for Windows Infrastructure installed and I am getting those reports. From Active Directory drop-down, go to Users&amp;gt;&amp;gt;User Reports&amp;gt;&amp;gt;Domain Accounts: New, or Domain Accounts: Deleted. Works!&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 12:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455796#M10646</guid>
      <dc:creator>dharveynswccd</dc:creator>
      <dc:date>2019-05-17T12:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: active directory new create and delete user query</title>
      <link>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455797#M10647</link>
      <description>&lt;P&gt;yes,i put wineventloglog:security input on my dc, but when i create user it doesn't show any log on my app.&lt;/P&gt;</description>
      <pubDate>Sat, 18 May 2019 14:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455797#M10647</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2019-05-18T14:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: active directory new create and delete user query</title>
      <link>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455798#M10648</link>
      <description>&lt;P&gt;can you tell me, what did you enable in group policy ?&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2019 03:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455798#M10648</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2019-05-19T03:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: active directory new create and delete user query</title>
      <link>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455799#M10649</link>
      <description>&lt;P&gt;Could it be the Active Directory audit policy needs to be set to log these events? &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/MSExchange/3.5.2/DeployMSX/ConfigureActiveDirectoryauditpolicy"&gt;https://docs.splunk.com/Documentation/MSExchange/3.5.2/DeployMSX/ConfigureActiveDirectoryauditpolicy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 10:14:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/active-directory-new-create-and-delete-user-query/m-p/455799#M10649</guid>
      <dc:creator>danan5</dc:creator>
      <dc:date>2019-07-24T10:14:27Z</dc:date>
    </item>
  </channel>
</rss>

