Getting Data In

Audit who makes changes to Active Directory

dshipman
New Member

Hi,

I'm looking into using Splunk to report on Active Directory. I've installed the free edition on a test domain & set it up to monitor the directory schema. It seems to be picking up events but I'm unable to find any information about who makes changes (e.g. account create/delete) - is this possible at all?

Thanks in advance for any advice

0 Karma

MarioM
Motivator

You should install and look at this app first :

windows-security-operations-center

0 Karma

xxmarkxx8
New Member

Hi there,

I know this is an old thread but I am having the same issue as above.
I have installed the windows security operations center app but it doesn't display which user made the changes to an AD object. I have tested Netwrix and that application can find the user details with no problem (so I know it is not an auditing settings problem)
Any help would be much appreciated.

Regards,

Mark B

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...