- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ish
Explorer
09-22-2021
06:52 AM
Hi
I want to set up a report on Splunk server to detect when a user is added to a security group
Can you please help what steps I have to take
Thanks
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-23-2021
07:02 AM
Your domain controllers must be sending Windows security events to Splunk. Then you can search the wineventlog (or whatever you call it) index for events 4728, 4732, and 4756.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ish
Explorer
09-27-2021
06:36 AM
Thanks very much
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-23-2021
07:02 AM
Your domain controllers must be sending Windows security events to Splunk. Then you can search the wineventlog (or whatever you call it) index for events 4728, 4732, and 4756.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
