Hello All,
In one of my server the access has been given to Adam, Brian and Charlie on the host "xyxxac.bus.com".
I need to know who have added these members into that server, Please let me know the exact Splunk query.
Also i have installed Splunk UF software on this server last week only, is it possible to pull the logs from this server for last month ??
Thanks,
Ramu.R
Hey @mailmetoramu,
You can check who added the users by collecting windows logs of the servers. If you have AD running then you'll have to collect logs from there to get that information.
More info on collecting windows logs here :
https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/MonitorWindowseventlogdata
More info on collecting AD logs here :
https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/MonitorActiveDirectory
Cheers,
David
windows server ? Linux Server ? Splunk Server ? Could you please give some details ?
Windows Server actually ..!!