All Apps and Add-ons

Resolving Windows Domain users in IIS logs

nathanclevenge1
New Member

I'm currently picking up IIS logs that have connecting usernames listed as "domain\username" . I'd like to resolve these to the Active Directory names ex: Firstname Lastname

Is this possible? If so, how would I go about doing it?

Tags (1)
0 Karma

pbrunel_splunk
Splunk Employee
Splunk Employee

One way might be to have a periodic dump of Active directory users into a lookup file using the SA for LDAP. The dump would include all relevant information like the domain, username, and first & last names for the users. You could then use a lookup to resolve the field in the logs to what's in AD.

Make sense? Can go into more detail if needed.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...