Alerting

How can I get Splunk to alert on changes to specific groups in AD?

Frederik
New Member

I need to do the following:

  1. Specify groups that are to be monitored.
  2. Have a search that lists changes to these groups, including who did the change, what was changed and if a user or group was added or removed who that user or group is.
  3. Send an email to our with a report that list all new changes as soon as the change is performed.

How can I get this done?

Thanks

0 Karma

adonio
Ultra Champion

Hello Frederik,

Did you try the app for Windows Infrastructure?
https://splunkbase.splunk.com/app/1680/
it has prebuilt dashboards and reports for the requirements specified.
check out the docs as well, this one for example:
http://docs.splunk.com/Documentation/MSApp/1.4.1/Reference/GroupChanges
Navigate around and check other feature of this app

Hope it helps

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...