Alerting

Monitoring Active Directory groups, is it possible to send an email alert to the individual who was added or removed from the group?

8i5
Engager

We'd like to use Splunk to monitor active directory groups but rather than email a fixed address when there are changes, we'd like to send an email alert to the individual who was added or removed from the group.

How would we go about doing this?

lmyrefelt
Builder

It seems to be an app for that;

https://apps.splunk.com/app/1794/

🙂

0 Karma

f10353
New Member

Is there a sample search that could be shared for Active Directory Group changes (meaning additions or deletions)?

0 Karma

jkat54
SplunkTrust
SplunkTrust

There are similar searches in the app for windows infrastructure just need to be a bit inventive and send them to the sendemail command as a token, etc.

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...