Change Auditor/Active Roles integration scripts with Splunk
We have Active Roles Server 7.4.4 and Change Auditor 7.1.1 installed. We have "Change Auditor/Active Roles integration scripts" deployed. These work correctly for us and from Change Auditor we can see who has been the correct initiator who has carried out the actions in Active Roles. Our Security Department wants to use Splunk to control the correct initiators of the actions in Active Roles. Initially they connected to the event viewers of the Change Auditor agents on the domain controllers. But in these events the initiator does not appear. Where should Splunk connect to see the originating user performing the action in Active Roles?
Sign In Required
You need to be signed in and under a current maintenance contract to view premium knowledge articles.