Hi @cdavidsonbp The content packs might be helpful if you're running ITSI/ITE Work but you will still need to look at collecting the data. The Windows TA you referenced is a great starting point as it can collect AD events and win event logs that should help create the info you need. Have a look at these docs on AD Audit policy configuration, the docs are for the older exchange app but this functionality is now in the Add-on for Windows. https://docs.splunk.com/Documentation/MSExchange/4.0.4/DeployMSX/ConfigureActiveDirectoryauditpolicy Please let me know how you get on and consider upvoting/karma this answer if it has helped. Regards Will
... View more