The Users series of dashboards give you vision into the defense mechanisms of your Active Directory operations. They provide information on logon failures, attempts to controvert user security settings, and user utilization, as well as display audits and reports on all AD objects in your environment.
How to use this page
Each of the User dashboards has two sections: upper and lower. The upper section of the dashboard is a selection panel that lets you filter the user list based on the forests, sites, domains, and domain controllers that you choose. You can filter with multiple objects at a time. The lower portion of the dashboard displays additional information based on what you select on the top half.
You can also control how much data gets displayed by selecting the time range you desire in the time range picker on the upper right side of the dashboard.
This documentation applies to the following versions of Splunk® App for Windows Infrastructure (Legacy): 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.5.0, 1.5.1, 1.5.2, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4
Feedback submitted, thanks!