Splunk Search

List of AD groups a user was removed from

toontech
New Member

How do I get a list of AD groups a specific user was removed from in the last week please. 

We had a Helpdesk person accidentally remove AD groups for a user far earlier than they should have and whilst we can re-instate some memberships via user location, department knowledge etc there will be a lot more than that.

Any ideas please?

Labels (2)
0 Karma

gazzadownunder
New Member

Have a look at this article, which shows how to display group membership changes for a user based on AD replication data.

https://nettools.net/group-changes/

And this one which shows the members that have been removed from an individual group

https://nettools.net/howto-display-what-members-were-remove-from-a-group/

0 Karma

toontech
New Member

thank you for this, it appears we are not logging events for this code in Splunk. We had to make a manual effort to restore this users AD groups and I guess i'll have to ask for such events to be logged in future.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Search for EventCode=4729 and the user in question.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...