Getting Data In

Target data from specific Active Directory OU's

Mobyd
New Member

Hi,

     I am trying to gather data from a specific organisation unit in Active Directory and ignore everything else? I have tried with a transforms.conf to allow it but didn't seem to work.  I could sort of get it to work by writing a block for everything else but its a bit of a pain as the environment is shared.

Any one had any experience  doing this sort of thing?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Mobyd 

Please could you confirm - is this using an admon:// input?

If so you should be able to specify a "startingNode" which would the OU which you would like to monitor.

https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf#:~:text=startingNode%20%3D%20%3...

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Mobyd
New Member

Yes, that is correct. We are using admon in the default. I'll give that a go. Also, if I wanted to also limit it by that and then the destination IP, would I use a transforms.conf for that? Many Thanks

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...