<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic List of computers extracted from the computer in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434991#M172617</link>
    <description>&lt;P&gt;Scenario: In a way, the local admin user can be retrieved, the computer to remove the domain, and without the domain to list the list of people who use the computer&lt;/P&gt;</description>
    <pubDate>Fri, 08 Mar 2019 13:27:56 GMT</pubDate>
    <dc:creator>magun</dc:creator>
    <dc:date>2019-03-08T13:27:56Z</dc:date>
    <item>
      <title>List of computers extracted from the computer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434991#M172617</link>
      <description>&lt;P&gt;Scenario: In a way, the local admin user can be retrieved, the computer to remove the domain, and without the domain to list the list of people who use the computer&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 13:27:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434991#M172617</guid>
      <dc:creator>magun</dc:creator>
      <dc:date>2019-03-08T13:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: List of computers extracted from the computer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434992#M172618</link>
      <description>&lt;P&gt;And your question is???&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 13:46:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434992#M172618</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-08T13:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: List of computers extracted from the computer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434993#M172619</link>
      <description>&lt;P&gt;Can you phrase your question another way?&lt;BR /&gt;
I'm not sure i understand what you are asking.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 13:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434993#M172619</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-08T13:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: List of computers extracted from the computer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434994#M172620</link>
      <description>&lt;P&gt;How do I tell if local admin removes a computer from a domain&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 13:51:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434994#M172620</guid>
      <dc:creator>magun</dc:creator>
      <dc:date>2019-03-08T13:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: List of computers extracted from the computer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434995#M172621</link>
      <description>&lt;P&gt;How do I tell if local admin removes a computer from a domain&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 13:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434995#M172621</guid>
      <dc:creator>magun</dc:creator>
      <dc:date>2019-03-08T13:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: List of computers extracted from the computer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434996#M172622</link>
      <description>&lt;P&gt;1-  Do I find a list of local admin users&lt;BR /&gt;
2- How do I find out which local host is logged in?&lt;BR /&gt;
3- How do I find the list of hosts removed from these hosts in login&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 13:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434996#M172622</guid>
      <dc:creator>magun</dc:creator>
      <dc:date>2019-03-08T13:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: List of computers extracted from the computer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434997#M172623</link>
      <description>&lt;P&gt;That's a windows security question, not a splunk question, so you might be better of asking this on some windows user community or so. But perhaps someone comes by here who has experience with this specific use case.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 14:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434997#M172623</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-08T14:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: List of computers extracted from the computer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434998#M172624</link>
      <description>&lt;P&gt;Ok, a few terminology clarifications:&lt;/P&gt;

&lt;P&gt;A local admin can &lt;STRONG&gt;not&lt;/STRONG&gt; remove a computer from a domain.&lt;BR /&gt;
A local admin however, can switch a local computer account to a workgroup.&lt;/P&gt;

&lt;P&gt;This is problematic, because I do not believe the local system records if a workgroup membership is changed, and the domain controllers will be unaware that this change has been made.&lt;/P&gt;

&lt;P&gt;On the other hand, if the user was a domain admin, the DCs would log Event ID 4743.&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Your follow up questions:&lt;/EM&gt;&lt;BR /&gt;
You can run a script (via a UF) to enumerate the users of the local admins group and index this data.  You could collect this data daily and then monitor for changes to this membership.&lt;/P&gt;

&lt;P&gt;Once you have a list of the user accounts with local admin rights, you can then look for 4624 events which mention these users to see when they login - these will be local events - again not shared with the DC&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Finding a list of computers removed&lt;/EM&gt; - that's super complicated!&lt;BR /&gt;
My best guess is that you want to query ldap for a list of all computer accounts and record their last login date (you will need to collect this from ALL domain controllers, because lastlogin is not replicated)&lt;BR /&gt;
Then you need to compare this list to all computers which are sending events to Splunk. If something is sending data to Splunk, more than 24 hours after the last computer account domain login, you could 'guess' that it had been removed from the domain.&lt;/P&gt;

&lt;P&gt;There are a lot of if's (and buts) in the above, and Splunk is probably not the correct tool on its own for this.&lt;BR /&gt;
I could ramble on about how no-one should have local admin rights, and other policy/technical limitations, but bottom line is if your users are doing things they should not be doing - you need to address that by removing their ability to do so.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 14:13:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-of-computers-extracted-from-the-computer/m-p/434998#M172624</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-08T14:13:34Z</dc:date>
    </item>
  </channel>
</rss>

