Splunk Search

get AD Computer with PowerShell

TheOnlyOne
Observer

Hello,

i have a powershell script that give me ad computer objects back.
it works perfect.
The Script run every 24h. Cron Schedule 0 */1440 * ? * *

Im not sure about the time settings. I will get every time the summary of AD Computer Objects

My search is:
sourcetype=AD DNSHostName="W10_1*" | stats count as Total

The Problem is i get every time differnt values back. At the moment i have set Date & TIme Range last 24h.
At 2 o clock i get 200 Objects back, at 3 o clock i get 130 Objects back 😞

I get from the script every 24h new data. in this Time i will see the right values.

Can anybody help me?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...