Getting Data In
Highlighted

Splunk 6.1 how to find a listing of local admins on all workstations and servers

Path Finder

Hey guys,

I was wondering if there is a search that would list all local admin accounts on a workstation or server in my windows domain?

Tags (3)
0 Karma
Highlighted

Re: Splunk 6.1 how to find a listing of local admins on all workstations and servers

Super Champion

You would need to monitor an output that contains the list of local admins, and that does not happen automatically on Windows systems.

You could create a script to run on a schedule that generates a list of local admins, and read that data into Splunk. The command to run in the script would be this I think:
net localgroup administrators

Highlighted

Re: Splunk 6.1 how to find a listing of local admins on all workstations and servers

Path Finder

Thanks that looks like it works. But how would I output this to a file? Can i create a new file in the Splunk forwarder directory on the remote server?

0 Karma
Highlighted

Re: Splunk 6.1 how to find a listing of local admins on all workstations and servers

Path Finder