<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128934#M10455</link>
    <description>&lt;P&gt;People....I am confused like big time here....!!&lt;/P&gt;

&lt;P&gt;Is there any other add-on than &lt;STRONG&gt;Splunk Supporting Add-on for Active Directory&lt;/STRONG&gt; ??  &lt;/P&gt;</description>
    <pubDate>Fri, 13 Feb 2015 09:36:04 GMT</pubDate>
    <dc:creator>tsekali</dc:creator>
    <dc:date>2015-02-13T09:36:04Z</dc:date>
    <item>
      <title>Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128928#M10449</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;

&lt;P&gt;I am trying to configure the Splunk App for Windows Infrastructure. My topology includes 2 Windows Domain Controllers, one Windows Exchange Server, one win File Server, and 2 cisco devices. Windows machines are running a universal forwarder each, an indexer runs splunk enterprise 6.2.1 on ubuntu 14 and there is no Search Head. The indexer is responsible for both indexing and searching. &lt;/P&gt;

&lt;P&gt;About the app, the following is set up: &lt;BR /&gt;
Splunk v6.2.1&lt;BR /&gt;
Splunk Add-on for Microsoft Windows v4.7.3&lt;BR /&gt;
Splunk Supporting Add-on for Microsoft Windows Active Directory v2.0.1&lt;/P&gt;

&lt;P&gt;The user with winfra-admin user role and everything is marked with a green "tick". Besides that, continuing the wizard I get the following error: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Search "sourcetype="MSAD*" | head 5" did not return any events in the last 24 hours 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I read that &lt;EM&gt;Splunk Supporting Add-on for Microsoft Windows Active Directory&lt;/EM&gt; should be installed on the search head (which is not present in my topology because I found there is no need to have one). Does anyone know what might be the problem?&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 09:21:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128928#M10449</guid>
      <dc:creator>tsekali</dc:creator>
      <dc:date>2015-02-06T09:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128929#M10450</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Have you added the AD relevant TA:s to the domain controllers? MSAD data is generally grabbed through powershell scripts running on the domain controller. (You need powershell execution rights as well for this to work)&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 12:58:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128929#M10450</guid>
      <dc:creator>jofe</dc:creator>
      <dc:date>2015-02-06T12:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128930#M10451</link>
      <description>&lt;P&gt;Thanks for your answer!&lt;BR /&gt;
Do you mean the &lt;STRONG&gt;Splunk Supporting Add-on for Microsoft Windows Active Directory v2.0.1&lt;/STRONG&gt; ? I have this one installed on the indexer and it is marked as &lt;STRONG&gt;OK&lt;/STRONG&gt;. &lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 08:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128930#M10451</guid>
      <dc:creator>tsekali</dc:creator>
      <dc:date>2015-02-10T08:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128931#M10452</link>
      <description>&lt;P&gt;Also, in the documentation I see that  &lt;EM&gt;The Splunk Supporting Add-on for Active Directory can be installed on a search head.&lt;BR /&gt;
It does not perform any function when installed on a forwarder or indexer&lt;/EM&gt; .  Am I doing something wrong?&lt;BR /&gt;
My topology does not have a search head. Am I able to setup this app ??&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 09:00:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128931#M10452</guid>
      <dc:creator>tsekali</dc:creator>
      <dc:date>2015-02-10T09:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128932#M10453</link>
      <description>&lt;P&gt;If you do not have a search head in your topology, then your indexer is the search head by default. So there is no issue there.&lt;/P&gt;

&lt;P&gt;The data check for Active Directory is failing. This is because either:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The &lt;CODE&gt;msad&lt;/CODE&gt; index does not exist on your indexer&lt;/LI&gt;
&lt;LI&gt;The domain controllers are not sending data to the &lt;CODE&gt;msad&lt;/CODE&gt; index - they only do this if you installed the correct Active Directory add-on in the universal forwarder on each DC.&lt;/LI&gt;
&lt;LI&gt;The user has not been set up to search the &lt;CODE&gt;msad&lt;/CODE&gt; index by default.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;More info at the Splunk App for Windows Infrastructure &lt;A href="http://docs.splunk.com/Documentation/MSApp/1.1.1/MSInfra/TroubleshoottheSplunkAppforWindowsInfrastructure"&gt;Troubleshooting Page&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2015 00:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128932#M10453</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2015-02-11T00:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128933#M10454</link>
      <description>&lt;P&gt;Like malmoore says,&lt;/P&gt;

&lt;P&gt;You need more than the configuration on the search head / indexer for this to work. Please review his answer and verify that you have an MSAD index, and that you have installed the correct addon on the DOMAIN CONTROLLERS.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2015 10:22:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128933#M10454</guid>
      <dc:creator>jofe</dc:creator>
      <dc:date>2015-02-11T10:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128934#M10455</link>
      <description>&lt;P&gt;People....I am confused like big time here....!!&lt;/P&gt;

&lt;P&gt;Is there any other add-on than &lt;STRONG&gt;Splunk Supporting Add-on for Active Directory&lt;/STRONG&gt; ??  &lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 09:36:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128934#M10455</guid>
      <dc:creator>tsekali</dc:creator>
      <dc:date>2015-02-13T09:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128935#M10456</link>
      <description>&lt;P&gt;No. There are no other add-ons than the ones you listed. As well, the Splunk Supporting Add-on for Active Directory is not applicable to the problems you experience.&lt;/P&gt;

&lt;P&gt;Please read my response from 2 days ago as a starting point.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 23:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-am-I-getting-an-error-trying-to-configure-the-Splunk-App-for/m-p/128935#M10456</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2015-02-13T23:41:29Z</dc:date>
    </item>
  </channel>
</rss>

