Hello everyone.
Tell me there is such an stanza - [admon://] in addon Splunk_TA_Windows for monitoring AD.
I activated it and rolled into all controllers.
Began to flow various events of changes to AD.
But I do not see events when the user is added to some group or remove from it.
Earlier was another addon - https://docs.splunk.com/Documentation/DCADAddon/1.0.1/DCADAddon/Configuretheadd-ons
But since 2019, it is not supported and the entire functionality was transferred to SPLUNK Add-on for Windows.
How to setup stanza Splunk_TA_Windows to monitor and change in groups in AD ?