<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk for AD - Group Policy Changes Query in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20821#M447</link>
    <description>&lt;P&gt;I seem to get the same thing- Trying to figure out a work around as the AD guys would love to see Group Policy Changes. &lt;/P&gt;

&lt;P&gt;ERROR: com.unboundid.ldap.sdk.LDAPException: The provided string could not be decoded as a DN because no equal sign was found after the RDN attribute '{6504ceb9-3800-474d-b76e-7a4acf73cf4c}'.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2013 21:04:16 GMT</pubDate>
    <dc:creator>mbalasko</dc:creator>
    <dc:date>2013-04-02T21:04:16Z</dc:date>
    <item>
      <title>Splunk for AD - Group Policy Changes Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20818#M444</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
Has anyone come across an issue where the Group Policy Change Management information wont load?&lt;/P&gt;

&lt;P&gt;I discovered its because the "Object_Name" is not a DN value sometimes.&lt;/P&gt;

&lt;P&gt;When I run this:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
eventtype=msad-ad-access Object_Type="groupPolicyContainer" | eval adminuser=src_nt_domain."\".src_user | eval Object_Name=replace(Object_Name,"}CN","},CN") | stats count values(Object_Name) by host&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I get variations like this:&lt;BR /&gt;
CN={6426A7DE-BDD3-4124-AD09-93782F200DE0},CN=Policies,CN=System,DC=domain&lt;BR /&gt;
{44e14ec4-6218-40bd-bbc1-bf16d5addb58}&lt;/P&gt;

&lt;P&gt;Why would that be? &lt;/P&gt;

&lt;P&gt;I confirmed my DS log entries sometimes have either notation even for the same server. &lt;/P&gt;

&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20818#M444</guid>
      <dc:creator>BP9906</dc:creator>
      <dc:date>2020-09-28T13:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for AD - Group Policy Changes Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20819#M445</link>
      <description>&lt;P&gt;I've not seen the GUID version before.  I normally see the full DN - either complete or missing a comma (which is handled by the eval statement).  As a result, we'll have to deal with this as a bug and fix it in a future release.&lt;/P&gt;

&lt;P&gt;I've filed this in our bug tracking system.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 17:52:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20819#M445</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2013-02-06T17:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for AD - Group Policy Changes Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20820#M446</link>
      <description>&lt;P&gt;Do we know when this might be fixed? We have the same issue where the Group Policy is a GUID in the logs but have a full DN. Also this is generating the following error.&lt;/P&gt;

&lt;P&gt;External search command 'ldapfetch' returned error code 1. First 1000 (of 2586) bytes of script output: "Object_Name,&lt;STRONG&gt;mv_Object_Name,displayName,&lt;/STRONG&gt;mv_displayName,Access_Mask,&lt;STRONG&gt;mv_Access_Mask,Accesses,&lt;/STRONG&gt;mv_Accesses,Account_Domain,&lt;STRONG&gt;mv_Account_Domain,Account_Name,&lt;/STRONG&gt;mv_Account_Name,Caller_Domain,&lt;STRONG&gt;mv_Caller_Domain,Caller_Machine_Name,&lt;/STRONG&gt;mv_Caller_Machine_Name,Caller_User_Name,&lt;STRONG&gt;mv_Caller_User_Name,CategoryString,&lt;/STRONG&gt;mv_CategoryString,Client_Address,&lt;STRONG&gt;mv_Client_Address,Client_Domain,&lt;/STRONG&gt;mv_Client_Domain,Client_Machine_Name,&lt;STRONG&gt;mv_Client_Machine_Name,Client_User_Name,&lt;/STRONG&gt;mv_Client_User_Name,ComputerName,&lt;STRONG&gt;mv_ComputerName,Domain,&lt;/STRONG&gt;mv_Domain,EventCode,&lt;STRONG&gt;mv_EventCode,EventType,&lt;/STRONG&gt;mv_EventType,Handle_ID,&lt;STRONG&gt;mv_Handle_ID,Image_File_Name,&lt;/STRONG&gt;mv_Image_File_Name,Keywords,&lt;STRONG&gt;mv_Keywords,LogName,&lt;/STRONG&gt;mv_LogName,Logon_ID,&lt;STRONG&gt;mv_Logon_ID,Message,&lt;/STRONG&gt;mv_Message,New_Account_Name,&lt;STRONG&gt;mv_New_Account_Name,New_Domain,&lt;/STRONG&gt;mv_New_Domain,Object_Server,&lt;STRONG&gt;mv_Object_Server,Object_Type,&lt;/STRONG&gt;mv_Object_Type,OpCode,&lt;STRONG&gt;mv_OpCode,Operation_Type,&lt;/STRONG&gt;mv_Operation_Type,Parameter_1,&lt;STRONG&gt;mv_Parameter_1,Parameter_2,&lt;/STRONG&gt;mv_Parameter_2,Primary_Domain,__mv_Primary_Do"&lt;BR /&gt;
ERROR: com.unboundid.ldap.sdk.LDAPException: The provided string could not be decoded as a DN because no equal sign was found after the RDN attribute '{927ED781-C19A-4282-9E34-CE6C1116D6E3}&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20820#M446</guid>
      <dc:creator>hvandenb</dc:creator>
      <dc:date>2020-09-28T13:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for AD - Group Policy Changes Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20821#M447</link>
      <description>&lt;P&gt;I seem to get the same thing- Trying to figure out a work around as the AD guys would love to see Group Policy Changes. &lt;/P&gt;

&lt;P&gt;ERROR: com.unboundid.ldap.sdk.LDAPException: The provided string could not be decoded as a DN because no equal sign was found after the RDN attribute '{6504ceb9-3800-474d-b76e-7a4acf73cf4c}'.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2013 21:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20821#M447</guid>
      <dc:creator>mbalasko</dc:creator>
      <dc:date>2013-04-02T21:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for AD - Group Policy Changes Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20822#M448</link>
      <description>&lt;P&gt;What server Operating System, Platform (x86/x64), domain and forest levels are you seeing this on?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2013 16:57:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20822#M448</guid>
      <dc:creator>jbernt_splunk</dc:creator>
      <dc:date>2013-07-22T16:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for AD - Group Policy Changes Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20823#M449</link>
      <description>&lt;P&gt;2008 R2 OS, '2003 server' domain and forest level.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2013 17:00:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20823#M449</guid>
      <dc:creator>BP9906</dc:creator>
      <dc:date>2013-07-22T17:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for AD - Group Policy Changes Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20824#M450</link>
      <description>&lt;P&gt;Hello, did anyone got a solution for this?  I'm facing the same issue.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2014 08:42:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20824#M450</guid>
      <dc:creator>selim</dc:creator>
      <dc:date>2014-03-05T08:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for AD - Group Policy Changes Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20825#M451</link>
      <description>&lt;P&gt;Is there any fix for this problem ..we have the same issue&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2014 08:09:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-AD-Group-Policy-Changes-Query/m-p/20825#M451</guid>
      <dc:creator>arber</dc:creator>
      <dc:date>2014-09-18T08:09:53Z</dc:date>
    </item>
  </channel>
</rss>

