I am running Splunk 7.0.2 and I would like to monitor Active Directory GPO changes on splunk enterprise.
What is the best way to do that?
Is there any recommended app?
Thanks in advance.
please read here:
many answers also in this portal:
hope it helps
The logs are already forwarded to splunk, but i really need to create an alert when a GPO is modified, created etc.
Is there a way to do it?
look for EventCode=4735 for group changes, EventCode=4732 OR eventCode=4733 for user change
i use this website to verify what the event codes in windows mean:
put the needed event code at the end of url
EventCode=4732 OR eventCode=4733
This eventcode is only for group change, i need something for GPO.
are you looking for this?
ask your AD admin / owner what is the eventcoeds they are interested in, check you see it in splunk, write a search that answers your question