I need to do the following:
How can I get this done?
Thanks
Hello Frederik,
Did you try the app for Windows Infrastructure?
https://splunkbase.splunk.com/app/1680/
it has prebuilt dashboards and reports for the requirements specified.
check out the docs as well, this one for example:
http://docs.splunk.com/Documentation/MSApp/1.4.1/Reference/GroupChanges
Navigate around and check other feature of this app
Hope it helps