Getting Data In

User Account First Name Changed

anandhalagaras1
Contributor

Hi All,

One of the user account has been changed by someone and it got reflected in our Active Directory as well so we want to know who has changed it. 

Consider an example i.e. I am Anandh Alagarasan and my Firstname would be Anandh and Lastname would be Alagarasan.

So recently someone has updated my Firstname to Venkat. So in Active Directory when we checked the account i could see that my account is reflecting as Venkat Alagarasan.  So we want to know who had changed the FirstName of the user. Hence we want to know will it be captured in Wineventlogs ?

If yes, We want to find out who is the user who had changed the First name of the user account Anandh Alagarasan?

 

So kindly help to know how to pull the information using Search query.

 

0 Karma

anandhalagaras1
Contributor

Can anyone kindly help on my query please.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...