Getting Data In

How can I capture when members are removed from domain admins group?

Ghanayem1974
Path Finder

I am trying to identify when a member has been removed from security enabled groups such as domain admins, using index=wineventlog eventt_id=4729 but i am not finding anything with Group Name=Domain Admins?

0 Karma

dw385
Explorer

Are you pulling in the logs in XML format?
For non XML the field is Group_Name for Event ID 4729 (at least in my setup which should be the standard Windows TA).

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...