My organization uses obscure UserID's for AD authentication (e.g. abc9999). Is it possible to have Splunk search AD with the UserID and return the user's real name during a search?
prod\abc9999 is John Doe
FWIW, that app provides supporting functions for the Splunk App for Windows Infrastructure (http://apps.splunk.com/app/1680/). The Windows Infrastructure app does have some reports on AD users: http://docs.splunk.com/Documentation/MSApp/1.0.3/MSInfra/ActiveDirectoryReports#User_Reports.