Splunk Search

List of AD groups a user was removed from

toontech
New Member

How do I get a list of AD groups a specific user was removed from in the last week please. 

We had a Helpdesk person accidentally remove AD groups for a user far earlier than they should have and whilst we can re-instate some memberships via user location, department knowledge etc there will be a lot more than that.

Any ideas please?

Labels (2)
0 Karma

gazzadownunder
New Member

Have a look at this article, which shows how to display group membership changes for a user based on AD replication data.

https://nettools.net/group-changes/

And this one which shows the members that have been removed from an individual group

https://nettools.net/howto-display-what-members-were-remove-from-a-group/

0 Karma

toontech
New Member

thank you for this, it appears we are not logging events for this code in Splunk. We had to make a manual effort to restore this users AD groups and I guess i'll have to ask for such events to be logged in future.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Search for EventCode=4729 and the user in question.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...