All Apps and Add-ons

Resolving Windows Domain users in IIS logs

nathanclevenge1
New Member

I'm currently picking up IIS logs that have connecting usernames listed as "domain\username" . I'd like to resolve these to the Active Directory names ex: Firstname Lastname

Is this possible? If so, how would I go about doing it?

Tags (1)
0 Karma

pbrunel_splunk
Splunk Employee
Splunk Employee

One way might be to have a periodic dump of Active directory users into a lookup file using the SA for LDAP. The dump would include all relevant information like the domain, username, and first & last names for the users. You could then use a lookup to resolve the field in the logs to what's in AD.

Make sense? Can go into more detail if needed.

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...