<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk App for Windows Infrastructure: What are the parameters for UNUSED user accounts report? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141877#M12306</link>
    <description>&lt;P&gt;Greetings,&lt;BR /&gt;
I am using the Splunk App for Windows Infrastructure. In the Active Directory portion there is a report specifically for UNUSED user accounts (Active Directory\Users\User Reports\Unused). I was wondering if anyone happens to know what the variable is on that report to denote an unused account? Is it that the user has not logged in within 30 days, 90 days, 6 months or ever? I'd like to initiate cleanup of these accounts but want to make sure I have all the right information/understanding.&lt;/P&gt;

&lt;P&gt;Thanks in advance   &lt;/P&gt;</description>
    <pubDate>Fri, 26 Sep 2014 17:24:37 GMT</pubDate>
    <dc:creator>grambo271</dc:creator>
    <dc:date>2014-09-26T17:24:37Z</dc:date>
    <item>
      <title>Splunk App for Windows Infrastructure: What are the parameters for UNUSED user accounts report?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141877#M12306</link>
      <description>&lt;P&gt;Greetings,&lt;BR /&gt;
I am using the Splunk App for Windows Infrastructure. In the Active Directory portion there is a report specifically for UNUSED user accounts (Active Directory\Users\User Reports\Unused). I was wondering if anyone happens to know what the variable is on that report to denote an unused account? Is it that the user has not logged in within 30 days, 90 days, 6 months or ever? I'd like to initiate cleanup of these accounts but want to make sure I have all the right information/understanding.&lt;/P&gt;

&lt;P&gt;Thanks in advance   &lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2014 17:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141877#M12306</guid>
      <dc:creator>grambo271</dc:creator>
      <dc:date>2014-09-26T17:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: What are the parameters for UNUSED user accounts report?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141878#M12307</link>
      <description>&lt;P&gt;I'd be interested in knowing this as well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2015 21:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141878#M12307</guid>
      <dc:creator>darlas</dc:creator>
      <dc:date>2015-01-28T21:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: What are the parameters for UNUSED user accounts report?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141879#M12308</link>
      <description>&lt;P&gt;The Windows Infrastructure app defines an "Unused user account" as an account whose logon count is 0, meaning that they have never logged on.&lt;/P&gt;

&lt;P&gt;The search against the domain happens when you load the page and select the desired domain (which should be present if you've configured the app correctly.)&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2015 03:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141879#M12308</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2015-01-29T03:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: What are the parameters for UNUSED user accounts report?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141880#M12309</link>
      <description>&lt;P&gt;Thanks malmoore.  &lt;/P&gt;

&lt;P&gt;To clarify then how this works:  does the app has a list of users and looks for the existence of Windows login events for those users.  If none found for a given user then they are considered an "Unused user account".  Where does this list of users come from?  How can I see what list of users is being used?  (Professional Services set this up for us so I am missing some of the details &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; )  &lt;/P&gt;

&lt;P&gt;Or does the app look at some attribute in AD, like lastLogon, for all users to see which users do NOT have a value in the attribute?&lt;/P&gt;

&lt;P&gt;Thanks for helping me understand!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2015 17:39:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-What-are-the-parameters/m-p/141880#M12309</guid>
      <dc:creator>darlas</dc:creator>
      <dc:date>2015-01-29T17:39:14Z</dc:date>
    </item>
  </channel>
</rss>

