Can´t find the event when I delete a user in AD.
Is there any special config to get this info?
Using Splunk 4.3 on windows 2008 R2 server
You can get this information by using the splunk-admon.exe data input. Check out http://docs.splunk.com/Documentation/Splunk/latest/Data/AuditActiveDirectory
You can get this information by using the splunk-admon.exe data input. Check out http://docs.splunk.com/Documentation/Splunk/latest/Data/AuditActiveDirectory