All Apps and Add-ons

MS Windows AD Objects App Custom Fields

JHannan
Explorer

Is there a method to add custom AD Attributes from the AD Objects to the AD Object KV Stores in the MS AD Objects App or are we better off using a separate search to set these objects in a "Supplemental" AD Objects KV Store?  Currently, the app maps most of the defaults AD Objects, but there are some that are not mapped that we'd like to add to the KV Store for use with other apps.

Labels (2)
0 Karma

jcooperFossil
Path Finder

Coming in years after this question was asked, because I've been trying to do the same and I finally figured it out today!

The TA is currently on version 4.1.1

To get additional fields to appear in AD_Obj_User you need to do the following:
Edit the macro `ms_obj_admon_base_out_user` and include the fields you want in the SPL for "fields" and "table"
Do the same for the macro `ms_obj_user_base_migrate` just in case.

The part I was missing for years up until now was you have to edit the KV Store to specify what fields are allowed to be stored.
Edit the Lookup (KV Store) AD_Obj_User (Collection name is AD_Obj_User_LDAP_list_kv) and add the desired fields.

Rebuild your lookup and you're good to go!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...