All Apps and Add-ons

Splunk App for Windows Infrastructure: How to get logon and logoff audit information for our network domain admins?

pateld
Explorer

Hi

Currently I am trying to configure "Splunk App for Windows Infrastructure". Our goal is audit Logon/Logoff Domain Administrator.
After downloading the app, I have configured it by using "Guided Setup" under "Tools and Settings" and perform required steps to enable this app.
For "Active Directory\User Overview", I can see the data, but for "Active Directory\User Audit" and "Active Directory/Administrator Audit" I don't see any data.

Am I missing anything here? How can I get logon/logoff audit information for our network domain admins?

Thanks

0 Karma

BenTan
Path Finder

Hi,

Not sure if this is related, we did face an issue with one of the Administrator Audit panels under the Active Directory section: Administrator Logons.

After troubleshooting, we discovered part of the search was incorrect which leads to inaccurate results return. The default search for the panel is as below:

eventtype=msad-successful-user-logons dest_nt_domain="$select242$" user="$select244$"|rename src as src_ip|`ip-to-host`|`fix-localhost`|lookup SiteInfo host|dedup consecutive=t Site,src_nt_host,src_ip|table _time,Site,src_nt_host,src_ip|rename src_nt_host as Workstation,src_ip as "IP Address"

Just remove the |rename src as src_ip and the panel should return the proper result.

Hope this help!

Get Updates on the Splunk Community!

Best Strategies to Optimize Observability Costs

 Join us on Tuesday, May 6, 2025, at 11 AM PDT / 2 PM EDT for an insightful session on optimizing ...

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...