Hello Community,
I am new in splunk.
I want to make a report with all AD User logon with the details the source and the destination host.
I want to have the possibility to have a daily and a weekly report. How to proceed ?
Thank you in advance.
Is the log in Splunk?
The log is not in splunk, I have just add the Domain Controller.
Monitoring Windows data with Splunk Enterprise
Please check here first.