Splunk Search

get AD Computer with PowerShell

TheOnlyOne
Observer

Hello,

i have a powershell script that give me ad computer objects back.
it works perfect.
The Script run every 24h. Cron Schedule 0 */1440 * ? * *

Im not sure about the time settings. I will get every time the summary of AD Computer Objects

My search is:
sourcetype=AD DNSHostName="W10_1*" | stats count as Total

The Problem is i get every time differnt values back. At the moment i have set Date & TIme Range last 24h.
At 2 o clock i get 200 Objects back, at 3 o clock i get 130 Objects back 😞

I get from the script every 24h new data. in this Time i will see the right values.

Can anybody help me?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...