Alerting

Active Directory - How to alert upon new group member?

mcrawford44
Communicator

Per the title, How would one go about creating an alert that triggered on a new group member in Active Directory.

I understand you can trigger on event counts, however can you trigger on an addition over historical counts?

I'm currently playing around with a query that will display records within a short window of time behind the current time ( say 1-10 minutes ), and if the count of this > 1 it would trigger an email alert.

I'm curious if there is a better way to do this.

Thanks!

0 Karma

scottsavaresevi
Path Finder

Do a google search for microsoft event 4728 (I don't have enough Karma to post external links... sorry). Its the event for new users to security groups. If you send your AD logs into splunk you should be able to search for those events in Splunk. Then create an alert based on the appearance of that action. I found these instructions that can help you set an alert up. http://docs.splunk.com/Documentation/Splunk/6.1.3/Alert/Alertexamples

Hope that helps.

mcrawford44
Communicator

I should have specified we are only indexing the active directory structure with admon. There are no forwarders on the domain controllers.

0 Karma

brooklynotss
Path Finder
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...