<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No results found in the ADChanges in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512562#M2958</link>
    <description>In the "Search macros" screen, click on "Permissions" on the "select_winseclog_events" line and change the sharing to Global.&lt;BR /&gt;Then go back to your search and replace the backticks around the macro name. It should work now.</description>
    <pubDate>Wed, 05 Aug 2020 14:07:04 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-08-05T14:07:04Z</dc:date>
    <item>
      <title>When trying to create an audit for AD changes, why do we have No results found?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512283#M2944</link>
      <description>&lt;P data-unlink="true"&gt;I need to create an audit for AD changes and have followed all steps in&amp;nbsp;https://support.logbinder.com/SuperchargerKB/50135/8-Install-Supercharger-with-Splunk-Light-and-the-Splunk-App-for-LOGbinder&amp;nbsp;. Logs are all showing when I search index=main but no results found in the dashboard and Logbinder for splunk AD changes. I followed some searches from the past threads. Please see attached results. Kindly assist on this. Thank you.&lt;/P&gt;
&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sourcetype.PNG" style="width: 921px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10015i0A0B58BF1C287D77/image-size/large?v=v2&amp;amp;px=999" role="button" title="sourcetype.PNG" alt="sourcetype.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="index.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10014i05102F102AD07D3F/image-size/large?v=v2&amp;amp;px=999" role="button" title="index.PNG" alt="index.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="elect_winseclog_events.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10017i6E3E99665CDC3C18/image-size/large?v=v2&amp;amp;px=999" role="button" title="elect_winseclog_events.PNG" alt="elect_winseclog_events.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="inputlookup.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10016iDF2261AA4D3140CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="inputlookup.PNG" alt="inputlookup.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="event logs in index=main.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10019iAAD25E94C65EE327/image-size/large?v=v2&amp;amp;px=999" role="button" title="event logs in index=main.PNG" alt="event logs in index=main.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="no results found.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10018i1086C474AC04D77B/image-size/large?v=v2&amp;amp;px=999" role="button" title="no results found.PNG" alt="no results found.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 13:48:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512283#M2944</guid>
      <dc:creator>genldupali</dc:creator>
      <dc:date>2022-08-09T13:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512365#M2946</link>
      <description>Please share the searches used in the dashboard shown in the last screen shot.&lt;BR /&gt;If that dashboard uses the searches shown in the previous screen shots, then the problem may be the errors in the third and fourth searches. Once you resolve those errors the dashboard may show data.</description>
      <pubDate>Tue, 04 Aug 2020 12:41:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512365#M2946</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-04T12:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512380#M2947</link>
      <description>&lt;P&gt;Thank you for your reply. No results found for all filters in the dashboard. For example, under AD changes account changes by domain:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class="highlighted"&gt;search [ | inputlookup domain_controllers | fields ComputerName ] (index=wineventlog OR index=main) eventtype=WinSecLog EventCode=4738 | search NOT [ search [ | inputlookup domain_controllers | fields ComputerName ] (index=wineventlog OR index=main) eventtype=WinSecLog (EventCode=4738 OR EventCode=4720) |transaction maxspan=1s startswith=4720 endswith=4738 | fields _time TargetAccountName ] | eval Account_Expires_timestamp=strptime(Account_Expires,"%m/%d/%Y %H:%M:%S %p") | where (Logon_Hours=="All" OR match(_raw,"Account Enabled") OR Account_Expires=="&amp;lt;never&amp;gt;" OR Account_Expires_timestamp&amp;gt;_time OR User_Principal_Name!="-" OR SAM_Account_Name!="-" OR match(_raw,"'Smartcard Required'\s*-\s*Disabled") OR match(_raw,"'Don't Expire Password'\s*-\s*Enabled") OR match(_raw,"'Not Delegated'\s*-\s*Disabled") OR User_Workstations="&amp;lt;value not set&amp;gt;" ) | append [search [ | inputlookup domain_controllers | fields ComputerName ] (index=wineventlog OR index=main) eventtype=WinSecLog (EventCode=4720 OR EventCode=4725 OR EventCode=4726 ) ] | eval type=case(EventCode=4738,"Significant Change",EventCode=4720,"New user",EventCode=4725 OR EventCode=4726,"Deleted/Disabled")&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;I found some of the event codes like 4726 in main=index logs so there should be something reflected in the dashboard. How do I solve error:&amp;nbsp;&lt;SPAN&gt;Error in 'SearchParser': The search specifies a macro 'select_winseclog_events' that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information. . when I search for&amp;nbsp;`select_winseclog_events` (EventCode=4932 OR EventCode=4768)?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The fourth image is now resolved when I removed the "|". Please help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="inputlookup.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10033i574364ADAD1BCE46/image-size/large?v=v2&amp;amp;px=999" role="button" title="inputlookup.PNG" alt="inputlookup.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 13:39:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512380#M2947</guid>
      <dc:creator>genldupali</dc:creator>
      <dc:date>2020-08-04T13:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512387#M2948</link>
      <description>&lt;LI-CODE lang="markup"&gt;The search specifies a macro 'select_winseclog_events' that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.&lt;/LI-CODE&gt;&lt;P&gt;The error seems pretty clear about the cause of the error and how to resolve it:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure you have the right macro name&lt;/LI&gt;&lt;LI&gt;Make sure you have permission to read the macro&lt;/LI&gt;&lt;LI&gt;Make sure the macro is shared so you can access it&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you obtained the search from an on-line search, you may need to install an app that defines the macro.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;inputlookup&lt;/FONT&gt; is a generating command so it must be preceded by a pipe.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 14:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512387#M2948</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-04T14:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512531#M2952</link>
      <description>&lt;P&gt;Hello.&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are my macros. Do I need this&amp;nbsp;`select_winseclog_events`&amp;nbsp; macros to reflect data to the dashboard? Can you please help me how can I add this please? I was not able to find app that defines the macro. Thank you.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="macros.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10052iCAD2F53C89F1A7FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="macros.PNG" alt="macros.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 10:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512531#M2952</guid>
      <dc:creator>genldupali</dc:creator>
      <dc:date>2020-08-05T10:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512542#M2955</link>
      <description>&lt;P&gt;If your search uses a macro then you must have a definition for that macro.&amp;nbsp; Where did you get the search if the macro did not come with it?&lt;/P&gt;&lt;P&gt;The screen shot shows only those macros visible to the Search &amp;amp; Reporting app.&amp;nbsp; We already know the macro is not on that list because of the error message.&amp;nbsp; Select "All" from the App menu to see all macros.&amp;nbsp; If the one you're using still isn't on the list then you'll have to create one.&lt;/P&gt;&lt;P&gt;The first Google hit for 'select_winseclog_events' turned up this definition, which may be suitable for you.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[select_winseclog_events]
definition = (index=wineventlog OR index=main) eventtype=WinSecLog&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 12:49:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512542#M2955</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-05T12:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512552#M2956</link>
      <description>&lt;P&gt;I see it now thanks. i removed the ' from 'select_winseclog_events' (EventCode=4726 OR EventCode=4768). But still no result found although these events are present in the index=main logs. Kindly help on finding how to reflect this logs on the ADChanges like the last image&amp;nbsp; from splunk webinar.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="event code.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10055iAA535D4FCEAA9452/image-size/large?v=v2&amp;amp;px=999" role="button" title="event code.PNG" alt="event code.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="no results found.PNG" style="width: 640px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10056iB6AFB0DA3BDE13B3/image-size/large?v=v2&amp;amp;px=999" role="button" title="no results found.PNG" alt="no results found.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="macros.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10057i7FF0630BA7E84378/image-size/large?v=v2&amp;amp;px=999" role="button" title="macros.PNG" alt="macros.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="from webinar.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10058iC32CA97C30C73CB7/image-size/large?v=v2&amp;amp;px=999" role="button" title="from webinar.PNG" alt="from webinar.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 13:24:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512552#M2956</guid>
      <dc:creator>genldupali</dc:creator>
      <dc:date>2020-08-05T13:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512562#M2958</link>
      <description>In the "Search macros" screen, click on "Permissions" on the "select_winseclog_events" line and change the sharing to Global.&lt;BR /&gt;Then go back to your search and replace the backticks around the macro name. It should work now.</description>
      <pubDate>Wed, 05 Aug 2020 14:07:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512562#M2958</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-05T14:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512582#M2963</link>
      <description>&lt;P&gt;Thank you that worked. But still no result and did not reflect in the dashboard.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10066iBF31B0CFDAB90A77/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 14:39:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512582#M2963</guid>
      <dc:creator>genldupali</dc:creator>
      <dc:date>2020-08-05T14:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512589#M2966</link>
      <description>&lt;P&gt;Now I don't have any errors in searching but still no result. Kindly assist please. Thank you.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10067iAFF533BE1A974A22/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 14:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512589#M2966</guid>
      <dc:creator>genldupali</dc:creator>
      <dc:date>2020-08-05T14:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512591#M2967</link>
      <description>&lt;P&gt;Now you have a different problem to solve.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;A dashboard showing no results could mean there are events which mean the criteria or it could mean the search is not valid (wrong index, etc.).&lt;/P&gt;&lt;P&gt;Click in the search bar and type CTRL-Shift-E to expand all macros.&amp;nbsp; Verify the expansion makes sense in your Splunk environment.&amp;nbsp; Make changes as necessary.&amp;nbsp; Run that search in a new window so see f you get results.&amp;nbsp; If so, update the dashboard with the corrected search.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 14:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512591#M2967</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-05T14:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512600#M2969</link>
      <description>&lt;P&gt;This one is for account changes by Domain. I ran it in search bar but still no result. Sorry I'm a newbie so I am not sure if those macros are correct. But even simple search like&amp;nbsp;`select_winseclog_events` (EventCode=4726 OR EventCode=4768) and | inputlookup domain_controllers.. is not showing anything..&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10068i06418B6FA10866A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 15:25:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512600#M2969</guid>
      <dc:creator>genldupali</dc:creator>
      <dc:date>2020-08-05T15:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512617#M2971</link>
      <description>&lt;P&gt;The basic process for debugging a query is to start with the text before the first pipe and run it by itself to verify the results are expected.&amp;nbsp; Add one pipe at a time until the query breaks.&amp;nbsp; Then you know where to focus your efforts.&lt;/P&gt;&lt;P&gt;Subsearches should be run by themselves.&amp;nbsp; Add &lt;FONT face="courier new,courier"&gt;| format&lt;/FONT&gt; on the end (if not already present) to see what the subsearch will pass to the main search.&lt;/P&gt;&lt;P&gt;I suspect the &lt;FONT face="courier new,courier"&gt;inputlookup&lt;/FONT&gt; subsearches need &lt;FONT face="courier new,courier"&gt;| format&lt;/FONT&gt; added to them.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 16:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512617#M2971</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-05T16:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512693#M2973</link>
      <description>&lt;P&gt;Hello, Rich.&lt;/P&gt;&lt;P&gt;I think it is solved now. Changed&amp;nbsp;select_winseclog_events definition to index=main. Thank you for your support.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 09:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/512693#M2973</guid>
      <dc:creator>gendupali</dc:creator>
      <dc:date>2020-08-06T09:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/608604#M13558</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224546"&gt;@genldupali&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you solve your problem?&lt;/P&gt;&lt;P&gt;I have the same problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Paulo&lt;/P&gt;</description>
      <pubDate>Sun, 07 Aug 2022 15:18:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/608604#M13558</guid>
      <dc:creator>paulopires16</dc:creator>
      <dc:date>2022-08-07T15:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: No results found in the ADChanges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/608612#M13559</link>
      <description>&lt;P&gt;The solution is at the top of this thread.&amp;nbsp; If your problem is similar, but the solution doesn't work for you then please post a new question.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Aug 2022 16:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/When-trying-to-create-an-audit-for-AD-changes-why-do-we-have-No/m-p/608612#M13559</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-07T16:16:21Z</dc:date>
    </item>
  </channel>
</rss>

