<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Target data from specific Active Directory OU's in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Target-data-from-specific-Active-Directory-OU-s/m-p/746186#M118596</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255549"&gt;@Mobyd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you confirm - is this using an admon:// input?&lt;/P&gt;&lt;P&gt;If so you should be able to specify a "startingNode" which would the OU which you would like to monitor.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf#:~:text=startingNode%20%3D%20%3Cstring%3E" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf#:~:text=startingNode%20%3D%20%3Cstring%3E&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Wed, 14 May 2025 12:26:15 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-05-14T12:26:15Z</dc:date>
    <item>
      <title>Target data from specific Active Directory OU's</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Target-data-from-specific-Active-Directory-OU-s/m-p/746184#M118594</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;I am trying to gather data from a specific organisation unit in Active Directory and ignore everything else? I have tried with a transforms.conf to allow it but didn't seem to work.&amp;nbsp; I could sort of get it to work by writing a block for everything else but its a bit of a pain as the environment is shared.&lt;/P&gt;&lt;P&gt;Any one had any experience&amp;nbsp; doing this sort of thing?&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 12:11:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Target-data-from-specific-Active-Directory-OU-s/m-p/746184#M118594</guid>
      <dc:creator>Mobyd</dc:creator>
      <dc:date>2025-05-14T12:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Target data from specific Active Directory OU's</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Target-data-from-specific-Active-Directory-OU-s/m-p/746186#M118596</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255549"&gt;@Mobyd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you confirm - is this using an admon:// input?&lt;/P&gt;&lt;P&gt;If so you should be able to specify a "startingNode" which would the OU which you would like to monitor.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf#:~:text=startingNode%20%3D%20%3Cstring%3E" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf#:~:text=startingNode%20%3D%20%3Cstring%3E&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 12:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Target-data-from-specific-Active-Directory-OU-s/m-p/746186#M118596</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-14T12:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Target data from specific Active Directory OU's</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Target-data-from-specific-Active-Directory-OU-s/m-p/746187#M118597</link>
      <description>&lt;P&gt;Yes, that is correct. We are using admon in the default. I'll give that a go. Also, if I wanted to also limit it by that and then the destination IP, would I use a transforms.conf for that? Many Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 12:48:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Target-data-from-specific-Active-Directory-OU-s/m-p/746187#M118597</guid>
      <dc:creator>Mobyd</dc:creator>
      <dc:date>2025-05-14T12:48:46Z</dc:date>
    </item>
  </channel>
</rss>

