Getting Data In

User Account First Name Changed

anandhalagaras1
Contributor

Hi All,

One of the user account has been changed by someone and it got reflected in our Active Directory as well so we want to know who has changed it. 

Consider an example i.e. I am Anandh Alagarasan and my Firstname would be Anandh and Lastname would be Alagarasan.

So recently someone has updated my Firstname to Venkat. So in Active Directory when we checked the account i could see that my account is reflecting as Venkat Alagarasan.  So we want to know who had changed the FirstName of the user. Hence we want to know will it be captured in Wineventlogs ?

If yes, We want to find out who is the user who had changed the First name of the user account Anandh Alagarasan?

 

So kindly help to know how to pull the information using Search query.

 

0 Karma

anandhalagaras1
Contributor

Can anyone kindly help on my query please.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...