All Apps and Add-ons

Why are there no results found for expired accounts and disabled account reports?

New Member


We have recently setup the Spunk App for Windows Infrastructure to monitor our Active Directory.
We are receiving the AD audit information from the daily changes etc, however the reports such as Expired accounts or Disabled accounts do not work, no results are found.

I have checked the configuration within Splunk Support for Active Directory and the test comes back as successful.

Struggling to work out where the issue lies?

Would appreciate some help / advice.

Karl Forster

0 Karma


Hi @Karl12347

Did you check your Audit Policies ? Perhaps you are not auditing those events.

0 Karma
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...