Alerting

How can I get Splunk to alert on changes to specific groups in AD?

New Member

I need to do the following:

  1. Specify groups that are to be monitored.
  2. Have a search that lists changes to these groups, including who did the change, what was changed and if a user or group was added or removed who that user or group is.
  3. Send an email to our with a report that list all new changes as soon as the change is performed.

How can I get this done?

Thanks

0 Karma

SplunkTrust
SplunkTrust

Hello Frederik,

Did you try the app for Windows Infrastructure?
https://splunkbase.splunk.com/app/1680/
it has prebuilt dashboards and reports for the requirements specified.
check out the docs as well, this one for example:
http://docs.splunk.com/Documentation/MSApp/1.4.1/Reference/GroupChanges
Navigate around and check other feature of this app

Hope it helps

0 Karma