Splunk Search

Active Directory Group Memberships

Inthegetto
Observer

I am new to splunk and trying to determine how to setup an alert when a user in active directory is in two different AD groups. For example if a user is in group A and B alert. Anyone have some direction on how to achieve this?

Labels (3)
0 Karma

tscroggins
Champion

@Inthegetto 

Splunk Supporting Add-on for Active Directory includes the ldapsearch command. When properly configured for your AD domain(s), you can search for users in both groups with an appropriate LDAP filter:

| ldapsearch search="(&(objectCategory=person)(sAMAccountName=*)(memberOf:1.2.840.113556.1.4.1941:=cn=GroupA,ou=Groups,DC=example,DC=com)(memberOf:1.2.840.113556.1.4.1941:=cn=GroupB,ou=Groups,DC=example,DC=com))"

Running as a scheduled search, you can trigger an alert when the result count is greater than 0.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...