Getting Data In

active directory enrichment of windows event logs

csutherland504
New Member

My company has its splunk instance set up in such a way that windows event logs are being enriched with AD information such as the users manager and their OU group etc etc. The system admin that set that up has since left the company and noone knows how it was done. Is there an add on or something with the forwarders that could be doing this? can this be configured to add other data to the logs?

Thank you

Labels (1)
0 Karma

DavidHourani
Super Champion

Hi @csutherland504,

Are you currently using ES ?

Usually data enrichment happens on search time with automatic lookup, so have a look at your automatic lookup configuration for the specific sourcetype that you're looking for. This can help you better understand where the extra fields you're seeing are coming from.

You can find details about automatic lookups here :
https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/DefineanautomaticlookupinSplunkWeb

Cheers,
David

0 Karma

adonio
Ultra Champion

probably the addon for active directory or just the [admon] stanza in inputs.conf somewhere, either on the windows TA, other app or the MS AD addon

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...