Is it possible to have Splunk search active director with a user's real name and return a UserID ?
Would this be what you are looking for?