Splunk Search

Search to get all domain user account modifications/additions/removals?

informatika
Loves-to-Learn

Hello, new to using splunk across a domain and I am attempting to get a query that details any domain user account changes. I want to pull change type, who changed the account, and date/time from /var/log/dirsrv logs . Any suggestions?

0 Karma

yuanliu
SplunkTrust
SplunkTrust

This is a search forum.  You need to describe your data, logic, and expected output in order to get suggestions.  If you are concerned about data in a particular app, you may get better luck in All Apps and Add-ons where some people may happen to be using the same app as you do; even there, you will need to tell people which app you are concerned about.

0 Karma

informatika
Loves-to-Learn

edited with some more specifics! it is pertaining to search

0 Karma

yuanliu
SplunkTrust
SplunkTrust

When describing data, you really need to give details, such as which (relevant) fields are available, a general idea about values of these fields; it is perhaps easier to illustrate samples (anonymize as needed).  By describing logic, I mean how do you deduce change type and who changed the account from such data, etc. (Sometimes logic can be obvious from sample data, sometimes not, all depending on characteristics of actual data.) If you have a specific presentation format in mind, it is best to illustrate, too. (None of these are obvious from your question.)

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...