Splunk Search

Applied Group Policy Objects for all domain joined computers report

cdavidsonbp
Observer

Hello,

I am trying to find a way to report on all Applied Group Policy Objects for all of our domain joined computers. This would be similar to running the following command:
        gpresult /r /scope computer

Is there a way that Splunk can gather all of this information as a report. I did see there was an app called Splunk App for Windows Infrastructure but it was EOLd. Is there anything new that would audit our computers?

Thanks,
Charlie

0 Karma

PickleRick
SplunkTrust
SplunkTrust

In order to get data from Splunk you must first get the data into Splunk. Splunk is a data processing platform but you need go have something to be processed. How would you get that data? Where from? If the only way to produce such data is running gpresult, you need to run it and store the results somehow in Splunk.

0 Karma

cdavidsonbp
Observer

Thanks, Kiran! I am reading up on this now.!

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@cdavidsonbp 

Have a look at the content packs:

https://docs.splunk.com/Documentation/ContentPackApp/latest/Overview/Overview#Available_content_pack... 

specifically

https://docs.splunk.com/Documentation/CPWindowsMon/1.3.0/CP/About 

and

https://docs.splunk.com/Documentation/CPWindowsDash/1.4.0/CP/About 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @cdavidsonbp 

The content packs might be helpful if you're running ITSI/ITE Work but you will still need to look at collecting the data. The Windows TA you referenced is a great starting point as it can collect AD events and win event logs that should help create the info you need.

Have a look at these docs on AD Audit policy configuration, the docs are for the older exchange app but this functionality is now in the Add-on for Windows.

https://docs.splunk.com/Documentation/MSExchange/4.0.4/DeployMSX/ConfigureActiveDirectoryauditpolicy

Please let me know how you get on and consider upvoting/karma this answer if it has helped.
Regards

Will

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...