Splunk Search
Highlighted

How to create a search for deleted OU?

New Member

Good day. Could you help me in the following situation?

I was informed that an OU had been removed from the active directory, which asked me to find who could have deleted it, look for the event code for that situation but I can't find the right search, so I would like help to see how I can find that information?
I hope I have been clear in the question

Thanks for the support.

0 Karma
Highlighted

Re: How to create a search for deleted OU?

SplunkTrust
SplunkTrust

I believe you need to look for EventCode 5141 in your WinEventLog index. The OU in question must have auditing enabled. See https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=5141.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: How to create a search for deleted OU?

New Member

thank you very much richgalloway, i will check

0 Karma