Splunk Search

get AD Computer with PowerShell

TheOnlyOne
Observer

Hello,

i have a powershell script that give me ad computer objects back.
it works perfect.
The Script run every 24h. Cron Schedule 0 */1440 * ? * *

Im not sure about the time settings. I will get every time the summary of AD Computer Objects

My search is:
sourcetype=AD DNSHostName="W10_1*" | stats count as Total

The Problem is i get every time differnt values back. At the moment i have set Date & TIme Range last 24h.
At 2 o clock i get 200 Objects back, at 3 o clock i get 130 Objects back 😞

I get from the script every 24h new data. in this Time i will see the right values.

Can anybody help me?

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...