Hi to All,
I need help with creating an Active Directory changes report.
I used Win Events like 4728, 4729, 4730 but could not print to PDF
Is there a search that will return all changes creation, deletion of global groups?
Thank you!
index=MyIndex EventCode IN (4728,4729,4730) user=*
| eval time=_time
| convert ctime(time)
| eval msg="A user "+user+" was "+action+" on the host "+host+" by "+src_nt_domain+"\\"+src_user+" at "+time
|table msg,EventCode,action,user,signature,status
Thank you for helping me out. Much appreciated!