Skip to main content
Answer

OnPrem AD Computer Context Data not enriching logs?

  • November 26, 2025
  • 3 replies
  • 21 views

JSpoorSonic
Forum|alt.badge.img+9

I am pulling in AD Context Logs

as per Collect Microsoft Windows AD logs  |  Google Security Operations  |  Google Cloud

 

For user accounts, I am seeing the Enrichment in my event logs, however for Computer objects I am not seeing this?

 

Here’s the context data

Image

But when I check event logs for that host:

Image

although the IP is there, which I doubt is from enrichment, the other attributes not… I need at least the role.

 

 

Best answer by JSpoorSonic

Issue has been fixed.

It was a matter of incorrect namespaces.

 

3 replies

Eoved
Forum|alt.badge.img+7
  • Bronze 1
  • December 1, 2025

Hi, I would start by checking the data ingestion process and the LDAP filter manually on a Windows server to see what results you get and confirm whether the information meets your needs. It’s possible that the data isn’t being ingested into the system at all. If all the data is being pulled correctly, you’ll likely need to work on enrichment fields and mapping within your SecOps instance.


JSpoorSonic
Forum|alt.badge.img+9
  • Author
  • Bronze 3
  • December 1, 2025

I see the data logs, see screenshot 1. So they are being ingested.


JSpoorSonic
Forum|alt.badge.img+9
  • Author
  • Bronze 3
  • Answer
  • December 4, 2025

Issue has been fixed.

It was a matter of incorrect namespaces.