Would like to know if there is any query available that will tell us the total number of disabled accounts in Active Directory for a given time period and how to get the rate of disablement.
The Splunk Security Essentials app has example queries for detecting disabled accounts. I think they use datamodels, but if you don't use DMs then you should be able to get the event codes from the DM for use in an ordinary query.