Splunk Enterprise

How to find the last change or modification on multiple AD groups?

New Member

I have a csv file containing the SAM accounts of 1200 AD groups and I need to find out the proper search query to find the last date of their modification or change.

Labels (1)
0 Karma

| inputlookup <lookup or filename>
| stats max(<field that's the date field>)


| inputlookup <lookup or filename>
| stats max(<field that's the date field>) BY displayName


And if you were wanting a more useful way

base search here that returns regular data
| lookup <lookupName> <fieldInLookup> AS <fieldInData> OUTPUT lastUpdate

Which assuming you fix up the lookup name, double-check the fieldInLookup vs. fieldInData order (I always get those backwards!) and change the fieldname 'lastUpdate' to whatever it is in your lookup, will output the lastUpdate for each ... "field" you match on.  Perhaps displayName or something, whatever it is that should match.

This might help:



0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...