Reporting

How to create a report when an account is created in active directory?

ekoumbakemal
Observer

Hello,

I want to have a report when an account is created in active directory?
How I can process it?

Thanks.

0 Karma

gcusello
Esteemed Legend

Hi @ekoumbakemal,
see my answer in https://answers.splunk.com/answers/776027/how-to-display-a-modification-on-the-active-direct-1.html

Anyway, you have to search in Splunk the EventCode=4720:

index=wineventlog EventCode=4720
| ...

but the problem is that usually you haven't these EventCodes because this audit isn't enabled by default in Domain Controllers, so you have to enable it following instructions in my answer.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...