Here is. If I use the CN name value with Powershell's Get-GPO cmdlet then it returns me the Display Name of the GPO but I want to get it from Splunk results. 02/10/2024 11:30:27 AM
LogName=Security
EventCode=5136
EventType=0
ComputerName=DC-01.EXAMPLEDOMAIN.local
SourceName=Microsoft Windows security auditing.
Type=Information
RecordNumber=26135
Keywords=Audit Success
TaskCategory=Directory Service Changes
OpCode=Info
Message=A directory service object was modified.
Subject:
Security ID: EXAMPLEDOMAIN\administrator
Account Name: Administrator
Account Domain: EXAMPLEDOMAIN
Logon ID: 0x92B8F
Directory Service:
Name: exampledomain.local
Type: Active Directory Domain Services
Object:
DN: CN={CFD494B1-9D7F-448B-AF8F-3B7B3ABF1AA8}CN=POLICIES,CN=SYSTEM,DC=EXAMPLEDOMAIN,DC=LOCAL
GUID: CN={CFD494B1-9D7F-448B-AF8F-3B7B3ABF1AA8}CN=Policies,CN=System,DC=exampledomain,DC=local
Class: groupPolicyContainer
Attribute:
LDAP Display Name: versionNumber
Syntax (OID): 2.5.5.9
Value: 196611
Operation:
Type: Value Added
Correlation ID: {8eaedf1e-827a-4ee8-8118-2b8e0ddb1133}
Application Correlation ID: -
... View more