Monitoring Splunk

need to build a query how to find out whose account is not showing no_access on splunk roles, who are disabled from AD?

anilkumarmeka
Observer

Hello guys
Hope you are doing great!
I want to configure a query, some guys are disabled in AD and also, in Splunk ES when i open the Identity Investigatior it is showing also a disabled (cn=*,ou=disabled,ou=united,ou=accounts,dc=global,dc=ual,dc=com)
But in users it showing his role on under the roles but it should be need to sho as no_access, 
Now I want build a query and create a alert

Can you please help me on this 

Ani

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...