Splunk Enterprise Security

is there a dashboard for tracking active Directory group changes and local host group changes?

jarose
New Member

We want to be able to use Splunk as an auditing tool for our groups local and to Active Directory groups. If changes to the groups accur, we want to be able to see that in a Splunk dashboard.

Labels (1)
0 Karma
1 Solution

ayush1906
Path Finder

hi Jarose,

Check out this link: Monitor Active Directory in Splunk

If link not visible: https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/MonitorActiveDirectory

alternatively, you can also try monitoring a log file that logs the changes made in the database with splunk file monitor.

View solution in original post

0 Karma

shivanshu1593
Builder

Yes you can. Splunk has a specific add on for AD. You can check it out. Here's its doc on how to configure and deploy it. I think it'll serve your purpose of bringing those logs into Splunk. Once logs are in, it's very easy to build the required dashboard.

https://docs.splunk.com/Documentation/SA-LdapSearch/3.0.1/User/ConfiguretheSplunkSupportingAdd-onfor...
Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

ayush1906
Path Finder

hi Jarose,

Check out this link: Monitor Active Directory in Splunk

If link not visible: https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/MonitorActiveDirectory

alternatively, you can also try monitoring a log file that logs the changes made in the database with splunk file monitor.

0 Karma

jarose
New Member

Do you have any info on how to get the local server groups modifications? Not AD.

Example: administrators group on the local machines.

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...