<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk App Windows Infrastructure upgrade - No &amp;quot;sourcetype=&amp;quot;MSAD*&amp;quot; found in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162764#M15137</link>
    <description>&lt;P&gt;I've recently upgraded to Splunk App for Windows Infrastructure 1.1.1 from version 1.0.4.  Previously I had no issues with Active Directory data detection or Splunk App for Active Directory(SA-ldapsearch) version 2.0.1 and can still successfully search for queries like '|ldapsearch domain=DOMAIN search="(cn=Administrator)"').  Since the upgrade, when I run through the first-time setup wizard I get the error, "ERROR: Search "sourcetype="MSAD*" | head 5" did not return any events in the last 24 hours" when checking for data being provided by the environment.&lt;/P&gt;

&lt;P&gt;I'm then provided with a link named, "Splunk Add-on for Microsoft Windows Active Directory for Splunk Universal Forwarder" however the link takes me to setup instruction for the Windows Infrastructure App.  Since I'm still able to perform ldapsearch queries from the search app I'd assume the Splunk App for Active Directory is working correctly.&lt;/P&gt;

&lt;P&gt;Also, when viewing the upgrade instruction(&lt;A href="http://docs.splunk.com/Documentation/MSApp/1.1.1/MSInfra/UpgradetheSplunkAppforWindowsInfrastructure"&gt;http://docs.splunk.com/Documentation/MSApp/1.1.1/MSInfra/UpgradetheSplunkAppforWindowsInfrastructure&lt;/A&gt;) you're instructed to download 'Splunk Supporting Add-on for Active Directory version 2.0.2 or later' however version 2.0.1 is the latest version I can currently find for download.&lt;/P&gt;

&lt;P&gt;I'd appreciate any insight as I've hit a wall and cannot proceed with the upgraded version of the Windows Infrastructure app.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Dec 2014 02:18:34 GMT</pubDate>
    <dc:creator>linusHillyard</dc:creator>
    <dc:date>2014-12-19T02:18:34Z</dc:date>
    <item>
      <title>Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162764#M15137</link>
      <description>&lt;P&gt;I've recently upgraded to Splunk App for Windows Infrastructure 1.1.1 from version 1.0.4.  Previously I had no issues with Active Directory data detection or Splunk App for Active Directory(SA-ldapsearch) version 2.0.1 and can still successfully search for queries like '|ldapsearch domain=DOMAIN search="(cn=Administrator)"').  Since the upgrade, when I run through the first-time setup wizard I get the error, "ERROR: Search "sourcetype="MSAD*" | head 5" did not return any events in the last 24 hours" when checking for data being provided by the environment.&lt;/P&gt;

&lt;P&gt;I'm then provided with a link named, "Splunk Add-on for Microsoft Windows Active Directory for Splunk Universal Forwarder" however the link takes me to setup instruction for the Windows Infrastructure App.  Since I'm still able to perform ldapsearch queries from the search app I'd assume the Splunk App for Active Directory is working correctly.&lt;/P&gt;

&lt;P&gt;Also, when viewing the upgrade instruction(&lt;A href="http://docs.splunk.com/Documentation/MSApp/1.1.1/MSInfra/UpgradetheSplunkAppforWindowsInfrastructure"&gt;http://docs.splunk.com/Documentation/MSApp/1.1.1/MSInfra/UpgradetheSplunkAppforWindowsInfrastructure&lt;/A&gt;) you're instructed to download 'Splunk Supporting Add-on for Active Directory version 2.0.2 or later' however version 2.0.1 is the latest version I can currently find for download.&lt;/P&gt;

&lt;P&gt;I'd appreciate any insight as I've hit a wall and cannot proceed with the upgraded version of the Windows Infrastructure app.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 02:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162764#M15137</guid>
      <dc:creator>linusHillyard</dc:creator>
      <dc:date>2014-12-19T02:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162765#M15138</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Have you &lt;A href="http://docs.splunk.com/Documentation/MSApp/1.1.0/MSInfra/TroubleshoottheSplunkAppforWindowsInfrastructure#No_data_types_found_after_upgrade"&gt;made sure that&lt;/A&gt; the user that you log into Splunk Enterprise with has the 'winfra-admin' role? That role lets you search the proper default indexes that come with the app.&lt;/P&gt;

&lt;P&gt;The Splunk Supporting Add-on for Active Directory is currently at version 2.0.1. The reference to 2.0.2 has been corrected. Apologies for any confusion.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 06:44:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162765#M15138</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2014-12-19T06:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162766#M15139</link>
      <description>&lt;P&gt;Yes, sorry.  I should've stated the Prerequisites checks are all successful(green check marks).  Also, I'm seeing no errors on the forwarders regarding the PS scripts used to collect AD info by the TA-DomainController-NT6 add on.  Again, this application wias working correctly with the previous version Splunk App Windows Inf 1.0.4.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 08:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162766#M15139</guid>
      <dc:creator>linusHillyard</dc:creator>
      <dc:date>2014-12-19T08:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162767#M15140</link>
      <description>&lt;P&gt;Right, it's the data check that is failing.&lt;/P&gt;

&lt;P&gt;Events with source type MSAD go into the 'msad' index by default.&lt;/P&gt;

&lt;P&gt;Make sure that the 'winfra-admin' role searches the 'msad', 'perfmon', and 'winevents' roles by default.&lt;/P&gt;

&lt;P&gt;In the Splunk system bar, select "Settings" &amp;gt; "Access controls." From there , click "Roles", then click "winfra-admin." Once you get to that page, scroll down to "Indexes searched by default." The three indexes I mentioned above should be in the "Selected Indexes" pane.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 19:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162767#M15140</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2014-12-19T19:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162768#M15141</link>
      <description>&lt;P&gt;I am having similar issues.  I am not even monitoring Active Directory DCs but have installed the Splunk Supporting Add-on for Active Directory and setup a service account for LDAP functionality.  I see data from the MSAD index but not a sourcetype. Data from the MSAD index has a sourcetype of "ActiveDirectory".&lt;/P&gt;

&lt;P&gt;And yes, I have met all the prerequisites however setup is giving me "ERROR: Search "sourcetype="MSAD*" | head 5" did not return any events in the last 24 hours".&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 22:46:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162768#M15141</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2014-12-19T22:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162769#M15142</link>
      <description>&lt;P&gt;The Splunk Supporting Add-on for Active Directory doesn't actually collect AD events. It performs LDAP queries against your AD DCs and returns events based on those queries. Those events have no source type.&lt;/P&gt;

&lt;P&gt;But it seems like you might have enabled the Active Directory input when you installed the universal forwarder. This is because "ActiveDirectory" is the default source type that gets assigned to default admon inputs. It's important not to enable any inputs when you install the UF because the TAs that come with the Windows Infrastructure app will take care of collecting all that information with the right source type.&lt;/P&gt;

&lt;P&gt;At this point it's best to just delete that data and then install the correct Active Directory add-on for your version of Windows Server into the universal forwarder that is on the domain controller. That way the data will be indexed correctly, and the app will see it. &lt;/P&gt;</description>
      <pubDate>Sat, 20 Dec 2014 00:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162769#M15142</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2014-12-20T00:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162770#M15143</link>
      <description>&lt;P&gt;I do not need to monitor AD DCs in my environment and only have member servers with the UF and TA installed and configured.  The admon input was enabled on my SH which I have disabled.  How do I get Splunk App Windows Inf to find data with the MSAD sourcetype to complete the guided setup?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Dec 2014 00:43:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162770#M15143</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2014-12-20T00:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162771#M15144</link>
      <description>&lt;P&gt;Ah! Right. Yes, unfortunately that is a bug, and we'll be addressing it in a point release.&lt;/P&gt;

&lt;P&gt;In the meantime, to get through setup, go ahead and deploy the Active Directory TA onto your SH to generate some dummy data. Once you have enough to get through setup (you only need about 5-10 events or so, turn it off.&lt;/P&gt;

&lt;P&gt;Apologies for the inconvenience.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Dec 2014 00:57:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162771#M15144</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2014-12-20T00:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162772#M15145</link>
      <description>&lt;P&gt;That worked.  I copied the TA-DomainController-NT6 app to the SH and I was able to complete the setup.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 20 Dec 2014 01:26:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162772#M15145</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2014-12-20T01:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162773#M15146</link>
      <description>&lt;P&gt;This is exactly what I needed, thanks for the suggestion.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Dec 2014 12:18:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162773#M15146</guid>
      <dc:creator>linusHillyard</dc:creator>
      <dc:date>2014-12-21T12:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162774#M15147</link>
      <description>&lt;P&gt;I have the same issue - what is the SH stand for.  I am bit of a newbie.  Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Dec 2014 20:15:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162774#M15147</guid>
      <dc:creator>schultet</dc:creator>
      <dc:date>2014-12-23T20:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162775#M15148</link>
      <description>&lt;P&gt;I am guessing SH is Splunk Search Head server.  I copied the TA-DomainController-NT6 but still get the same error.  I have two DCs with the UF on them -  I am only seeing some data forwarded from he First DC like password changes, unlocks and Administrator  logons.  The Splunk server is now reporting Administrator Logons, so I assume it is forwarding those.  Any other ideas how to seed the MSAD search  &lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2014 14:40:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162775#M15148</guid>
      <dc:creator>schultet</dc:creator>
      <dc:date>2014-12-24T14:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162776#M15149</link>
      <description>&lt;P&gt;Which directory did you copy the TA-DomainController-NT6 folder to?  Make sure it's copied to the etc\apps directory only on the Search Head.  You will also have to install the Splunk Supporting Add-on for Active Directory (SA-LDAPSearch) and configure an account Spunk can use to query AD.  Lastly, you will have to install the add-on on your DC universal forwarders.  You can manually copy the folders to them, or use a deployment server - the preferred method.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2014 15:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162776#M15149</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2014-12-24T15:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162777#M15150</link>
      <description>&lt;P&gt;We had a similar issue - did you make sure that msad where default search indexes?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2014 16:17:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162777#M15150</guid>
      <dc:creator>dolejh76</dc:creator>
      <dc:date>2014-12-24T16:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162778#M15151</link>
      <description>&lt;P&gt;Hi all, thanks for the direction, I'm having the same issue but making progress.  So now my DCs are sending to both index=msad and index=activedirectory but only the eventsource=msad is NOT working.  My DCs are 2012R2 is this a powershell issue?  I have the app installed and deployed on the DC but the eventsource=msad is still not coming in???&lt;/P&gt;

&lt;P&gt;TIA!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2014 16:46:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162778#M15151</guid>
      <dc:creator>pmac22</dc:creator>
      <dc:date>2014-12-24T16:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162779#M15152</link>
      <description>&lt;P&gt;Yes, in the Windows Infra app, there is a separate TA for 2012 servers. &lt;BR /&gt;
Go to &lt;A href="http://docs.splunk.com/Documentation/MSApp/latest/MSInfra/DownloadandconfiguretheSplunkAdd-onsforActiveDirectory"&gt;http://docs.splunk.com/Documentation/MSApp/latest/MSInfra/DownloadandconfiguretheSplunkAdd-onsforActiveDirectory&lt;/A&gt; for more information.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2014 16:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162779#M15152</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2014-12-24T16:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162780#M15153</link>
      <description>&lt;P&gt;I had the powershell add-on installed, but i needed my windows admin to tweak the powershell read/write.  It's no working perfectly.  Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2014 17:10:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162780#M15153</guid>
      <dc:creator>pmac22</dc:creator>
      <dc:date>2014-12-24T17:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162781#M15154</link>
      <description>&lt;P&gt;I have all the apps installed in the correct directory on my SH (a single server used for Splunk) E:\Program Files\Splunk\etc\apps&lt;/P&gt;

&lt;P&gt;on the SH,  I have the SA-ldapsearch in the etc\apps directory.  LDAP  is configured with a domain admin user currently.   I performed a test connection and it was successful.   &lt;/P&gt;

&lt;P&gt;I do have the same APPs installed on both Domain Controllers and one is forwarding events &lt;/P&gt;

&lt;P&gt;Splunk_TA_windows&lt;BR /&gt;
SplunkUniversalForwarder&lt;BR /&gt;
TA-DNSServer-NT6&lt;BR /&gt;
TA-DomainCOntrollerNT6&lt;/P&gt;

&lt;P&gt;Both DCs are 64bit - one is 2012r2 the other DC that is not forwarding events is 2008R2&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162781#M15154</guid>
      <dc:creator>schultet</dc:creator>
      <dc:date>2020-09-28T18:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162782#M15155</link>
      <description>&lt;P&gt;where do I check that setting?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Dec 2014 21:06:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162782#M15155</guid>
      <dc:creator>schultet</dc:creator>
      <dc:date>2014-12-26T21:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App Windows Infrastructure upgrade - No "sourcetype="MSAD*" found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162783#M15156</link>
      <description>&lt;P&gt;If you run Windows Server 2012R2, then you need to deploy the TA-DomainController2012R2 and the SA-ModularInput-Powershell add-ons to those DCs.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Dec 2014 05:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Windows-Infrastructure-upgrade-No-quot-sourcetype/m-p/162783#M15156</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2014-12-27T05:35:54Z</dc:date>
    </item>
  </channel>
</rss>

