How can I return the display name for unsuccessful logons with Splunk Support for Active Directory?
You'd need to use the ldapfilter command to pull back the user's Display Name from Active Directory.
http://docs.splunk.com/Documentation/SA-LdapSearch/2.1.2/User/Theldapfiltercommand
Assuming you're using the msad-failed-user-logons eventtype, you search would look something like this:
eventtype=msad-failed-user-logons |ldapfilter domain=$dest_nt_domain$ search="(objectClass=$src_user$)" attrs="displayName"