All Apps and Add-ons

Splunk Support for Active Directory: How to find all computers in AD and list those that are not sending logs to Splunk?

mcbradford
Contributor

We have the ldapsearch app installed. I would like to query AD and get a list of all the "ACTIVE" computers that match an OU, then see if these systems are sending logs to Splunk.

Thoughts???

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

ibondarets
Explorer

this one:

ldapsearch domain=SHELL search="(&(operatingSystem=Server)(objectCategory=computer))" attrs="CN,operatingSystem"

doesn't work by default ad requires changes to AD Forest replication.
This is because "Splunk Support for Active Directory" uses only Global Catalog requests and cannot perform regular LDAP requests for some reason.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...