Reporting

Is there a search that will return all changes creation, deletion of global groups?

DanAlexander1
Engager

Hi to All,

I need help with creating an Active Directory changes report. 

I used Win Events like 4728, 4729, 4730 but could not print to PDF 

Is there a search that will return all changes creation, deletion of global groups?

 Thank you!

Labels (1)
0 Karma

marysan
Communicator

index=MyIndex  EventCode IN (4728,4729,4730) user=*
| eval time=_time
| convert ctime(time)
| eval msg="A user "+user+" was "+action+" on the host "+host+" by "+src_nt_domain+"\\"+src_user+" at "+time
|table msg,EventCode,action,user,signature,status

DanAlexander1
Engager

Thank you for helping me out. Much appreciated!

0 Karma

marysan
Communicator

@DanAlexander1 
If your problem is resolved, then please click one of the "Accept as Solution" buttons to help future readers. 🙂

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...