Getting Data In

Target data from specific Active Directory OU's

Mobyd
New Member

Hi,

     I am trying to gather data from a specific organisation unit in Active Directory and ignore everything else? I have tried with a transforms.conf to allow it but didn't seem to work.  I could sort of get it to work by writing a block for everything else but its a bit of a pain as the environment is shared.

Any one had any experience  doing this sort of thing?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Mobyd 

Please could you confirm - is this using an admon:// input?

If so you should be able to specify a "startingNode" which would the OU which you would like to monitor.

https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf#:~:text=startingNode%20%3D%20%3...

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Mobyd
New Member

Yes, that is correct. We are using admon in the default. I'll give that a go. Also, if I wanted to also limit it by that and then the destination IP, would I use a transforms.conf for that? Many Thanks

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...