Splunk Search

get AD Computer with PowerShell

TheOnlyOne
Observer

Hello,

i have a powershell script that give me ad computer objects back.
it works perfect.
The Script run every 24h. Cron Schedule 0 */1440 * ? * *

Im not sure about the time settings. I will get every time the summary of AD Computer Objects

My search is:
sourcetype=AD DNSHostName="W10_1*" | stats count as Total

The Problem is i get every time differnt values back. At the moment i have set Date & TIme Range last 24h.
At 2 o clock i get 200 Objects back, at 3 o clock i get 130 Objects back 😞

I get from the script every 24h new data. in this Time i will see the right values.

Can anybody help me?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...