---
isPrivate: true
title: Active Directory
description: Learn more about the Active Directory pack.
breadcrumbs: Docs > Observability Pipelines > Packs > Active Directory
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Active Directory

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

## Overview{% #overview %}

{% image
   source="https://docs.dd-static.net/images/observability_pipelines/packs/active_directory.9bb196a895a54b3bc5fea9399f236727.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/observability_pipelines/packs/active_directory.9bb196a895a54b3bc5fea9399f236727.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The Active Directory pack" /%}

This pack processes Active Directory Domain Services events, including Kerberos authentication, directory-service changes, and DCSync replication abuse.

What this pack does:

- Parses Kerberos events
- Flags DCSync replication
- Drops routine renewals
