Getting Data In

User Account First Name Changed

anandhalagaras1
Contributor

Hi All,

One of the user account has been changed by someone and it got reflected in our Active Directory as well so we want to know who has changed it. 

Consider an example i.e. I am Anandh Alagarasan and my Firstname would be Anandh and Lastname would be Alagarasan.

So recently someone has updated my Firstname to Venkat. So in Active Directory when we checked the account i could see that my account is reflecting as Venkat Alagarasan.  So we want to know who had changed the FirstName of the user. Hence we want to know will it be captured in Wineventlogs ?

If yes, We want to find out who is the user who had changed the First name of the user account Anandh Alagarasan?

 

So kindly help to know how to pull the information using Search query.

 

0 Karma

anandhalagaras1
Contributor

Can anyone kindly help on my query please.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...