Reporting

Is there a search that will return all changes creation, deletion of global groups?

DanAlexander1
Engager

Hi to All,

I need help with creating an Active Directory changes report. 

I used Win Events like 4728, 4729, 4730 but could not print to PDF 

Is there a search that will return all changes creation, deletion of global groups?

 Thank you!

Labels (1)
0 Karma

marysan
Communicator

index=MyIndex  EventCode IN (4728,4729,4730) user=*
| eval time=_time
| convert ctime(time)
| eval msg="A user "+user+" was "+action+" on the host "+host+" by "+src_nt_domain+"\\"+src_user+" at "+time
|table msg,EventCode,action,user,signature,status

DanAlexander1
Engager

Thank you for helping me out. Much appreciated!

0 Karma

marysan
Communicator

@DanAlexander1 
If your problem is resolved, then please click one of the "Accept as Solution" buttons to help future readers. 🙂

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...