<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: howto://configure splunk&gt; to monitor active directory</title> <atom:link href="http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/feed/" rel="self" type="application/rss+xml" /><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/</link> <description>lest the tubes become overfull</description> <lastBuildDate>Tue, 15 May 2012 22:46:35 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-3011</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Mon, 07 May 2012 19:49:58 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-3011</guid> <description>It had nothing to do with Splunk, who are a great group of people and a great company.</description> <content:encoded><![CDATA[<p>It had nothing to do with Splunk, who are a great group of people and a great company.</p> ]]></content:encoded> </item> <item><title>By: Truffle</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-3008</link> <dc:creator>Truffle</dc:creator> <pubDate>Thu, 03 May 2012 21:56:44 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-3008</guid> <description>Why in the world did you have to take posts down?</description> <content:encoded><![CDATA[<p>Why in the world did you have to take posts down?</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-3007</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Thu, 03 May 2012 20:49:53 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-3007</guid> <description>Sorry Tim, I don&#039;t do splunk anymore, and had to take down several of my better splunk posts. Check out Michael Wilde&#039;s stuff at splunkninja.com. He has some great stuff that should help you out.</description> <content:encoded><![CDATA[<p>Sorry Tim, I don&#8217;t do splunk anymore, and had to take down several of my better splunk posts. Check out Michael Wilde&#8217;s stuff at splunkninja.com. He has some great stuff that should help you out.</p> ]]></content:encoded> </item> <item><title>By: Truffle</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-3004</link> <dc:creator>Truffle</dc:creator> <pubDate>Tue, 01 May 2012 19:07:34 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-3004</guid> <description>any update on this? I just got AD into splunk now I need to make it useful</description> <content:encoded><![CDATA[<p>any update on this? I just got AD into splunk now I need to make it useful</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-1615</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Tue, 15 Mar 2011 23:29:58 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-1615</guid> <description>Hi Erik,
Soon, where that just became a lot sooner than it was since now I know someone is interested.
Thanks for commenting, and please stand by. If you are in an immediate jam, there are some good posts in the Splunk&gt; forums that should help you get started.
Ed</description> <content:encoded><![CDATA[<p>Hi Erik,<br
/> Soon, where that just became a lot sooner than it was since now I know someone is interested.<br
/> Thanks for commenting, and please stand by. If you are in an immediate jam, there are some good posts in the Splunk&gt; forums that should help you get started.<br
/> Ed</p> ]]></content:encoded> </item> <item><title>By: Erik Curtis</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-1610</link> <dc:creator>Erik Curtis</dc:creator> <pubDate>Mon, 14 Mar 2011 23:10:58 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-1610</guid> <description>&lt;blockquote&gt;check back soon, as we’ll have a follow up post or two on querying/monitoring AD with splunk&lt;/blockquote&gt; Any eta on the follow up post?</description> <content:encoded><![CDATA[<blockquote><p>check back soon, as we’ll have a follow up post or two on querying/monitoring AD with splunk</p></blockquote><p> Any eta on the follow up post?</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-654</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Tue, 29 Jun 2010 13:58:35 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-654</guid> <description>&lt;em&gt;Hi Luke,
Sorry I didn&#039;t get to comments sooner (had a big server fall down go boom issue last night at work,) but I&#039;m glad you found your answer already. Use that as a pattern...many other events that you might want to report on like GPO changes, account resets, etc. will be found in the same manner. I have an upcoming post about these as well.
Thanks for dropping by!
Ed&lt;/em&gt;</description> <content:encoded><![CDATA[<p><em>Hi Luke,<br
/> Sorry I didn&#8217;t get to comments sooner (had a big server fall down go boom issue last night at work,) but I&#8217;m glad you found your answer already. Use that as a pattern&#8230;many other events that you might want to report on like GPO changes, account resets, etc. will be found in the same manner. I have an upcoming post about these as well.<br
/> Thanks for dropping by!<br
/> Ed</em></p> ]]></content:encoded> </item> <item><title>By: Luke</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-653</link> <dc:creator>Luke</dc:creator> <pubDate>Tue, 29 Jun 2010 03:51:15 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-653</guid> <description>ignore my last comment, I figured it out:
search sourcetype=&quot;WinEventLog:Security&quot; &quot;Message=Security Enabled Global Group Member&quot;L. :)</description> <content:encoded><![CDATA[<p>ignore my last comment, I figured it out:<br
/> search sourcetype=&#8221;WinEventLog:Security&#8221; &#8220;Message=Security Enabled Global Group Member&#8221;</p><p>L. <img
src='http://retrohack.com/_retroh_wp_root/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p> ]]></content:encoded> </item> <item><title>By: Luke</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-652</link> <dc:creator>Luke</dc:creator> <pubDate>Mon, 28 Jun 2010 22:45:15 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-652</guid> <description>nice howto :)have you discovered a way to run a splunk search for an AD update and determine who modified the object in AD?</description> <content:encoded><![CDATA[<p>nice howto <img
src='http://retrohack.com/_retroh_wp_root/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>have you discovered a way to run a splunk search for an AD update and determine who modified the object in AD?</p> ]]></content:encoded> </item> <item><title>By: Splunk</title><link>http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/comment-page-1/#comment-650</link> <dc:creator>Splunk</dc:creator> <pubDate>Fri, 25 Jun 2010 16:55:08 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/how-to-configure-splunk-to-monitor-active-directory/#comment-650</guid> <description>&lt;span class=&quot;topsy_trackback_comment&quot;&gt;&lt;span class=&quot;topsy_twitter_username&quot;&gt;&lt;span class=&quot;topsy_trackback_content&quot;&gt;RT @retrohack: New #retrohack post: howto://configure splunk&gt; to monitor active directory http://bit.ly/a17ATd&lt;/span&gt;&lt;/span&gt;</description> <content:encoded><![CDATA[<p><span
class="topsy_trackback_comment"><span
class="topsy_twitter_username"><span
class="topsy_trackback_content">RT @retrohack: New #retrohack post: howto://configure splunk&gt; to monitor active directory <a
href="http://bit.ly/a17ATd" rel="nofollow">http://bit.ly/a17ATd</a></span></span></span></p> ]]></content:encoded> </item> </channel> </rss>
<!-- Served from: retrohack.com @ 2012-05-18 11:39:40 by W3 Total Cache -->
