Splunk® App for Windows Infrastructure (Legacy)

Splunk App for Windows Infrastructure Reference

On October 20, 2021, the Splunk App for Windows Infrastructure will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Windows Dashboards and Reports.

User Overview

Exch 30 aduseroverview.png

The Users series of dashboards give you vision into the defense mechanisms of your Active Directory operations. They provide information on logon failures, attempts to controvert user security settings, and user utilization, as well as display audits and reports on all AD objects in your environment.

How to use this page

Each of the User dashboards has two sections: upper and lower. The upper section of the dashboard is a selection panel that lets you filter the user list based on the forests, sites, domains, and domain controllers that you choose. You can filter with multiple objects at a time. The lower portion of the dashboard displays additional information based on what you select on the top half.

You can also control how much data gets displayed by selecting the time range you desire in the time range picker on the upper right side of the dashboard.

Last modified on 30 November, 2016
DNS Performance   User Audit

This documentation applies to the following versions of Splunk® App for Windows Infrastructure (Legacy): 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.5.0, 1.5.1, 1.5.2, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters