Splunk Search

Quest ChangeAuditor

agonist_inhaler
Explorer

Hi, I am wondering if anyone have already user Splunk for Quest ChangeAuditor, I know by searching through google that this piece of software can monitor AD events, like logins, and account lock-outs and so on, they even have exchange and sql support, but I really don't know how it logs all these events. I am hoping someone is familiar enough on this software and can give any idea on its own logging system if its possible to splunk it.

Appreciate any inputs.

PS. I know generally that any plain text file splunk can read.

Tags (1)
0 Karma

ageld
Path Finder

Has anyone successfully accomplished the integration between Quest (Dell) ChangeAuditor and Splunk? I would love to be able to send ChangeAuditor logs to Splunk.

Thank you!

0 Karma

tomcochran
New Member

Is there any follow up info on how this could be done? I have been searching and it seems like there is little info especially now that ChangeAuditor is Dell owned.

0 Karma

bpiirala
New Member

Quest ChangeAuditor is an awesome product. You can't get that level of AD auditing anywhere else, and the UI makes it ridiculously easy to search and find audit info after the fact. You definitely don't need any event logging tools for this, but yes you could also use Splunk to collect ChangeAuditor's events too. Although for AD auditing, the ChangeAuditor UI is what you'd want to use.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...