<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Windows Infrastructure - deployment issues in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190165#M19381</link>
    <description>&lt;P&gt;OK, I think I'm getting somewhere.. I am able to run 'ldapsearch' using Splunk Support - LDAP Commands app. I can also see some indexes triggered by add-ons installed on DC (i.e. for TA-DomainController-2012R2 when executing: index=msad sourcetype=MSAD:NT6:Health).&lt;BR /&gt;
I still however have problem with Splunk App for Windows Infrastructure. When I'm running 'App Configuration' I'm not getting: Users, Computers and Groups. &lt;BR /&gt;
I was under impression that these are preconfigured in addons which I installed on the DCs but maybe these are not. What I should chec in inputs.conf? thanks&lt;/P&gt;</description>
    <pubDate>Fri, 22 Aug 2014 09:30:55 GMT</pubDate>
    <dc:creator>africates</dc:creator>
    <dc:date>2014-08-22T09:30:55Z</dc:date>
    <item>
      <title>Splunk App for Windows Infrastructure - deployment issues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190162#M19378</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm trying to deploy Splunk App for Windows Infrastructure on small AD environment (2 Domain Controllers and few other windows servers + 1 Splunk Indexer)&lt;/P&gt;

&lt;P&gt;I installed everything according to the App specification but I'm getting very little information via the App itself now. I can see that I do not get any info re users or groups etc.&lt;/P&gt;

&lt;P&gt;I noticed that powershell scripts aren't running OK i.e. below script should gather some Topology info but returns error (see the end of the post).&lt;/P&gt;

&lt;P&gt;Any ideas what could go wrong?&lt;/P&gt;

&lt;P&gt;[powershell://AD-Health]&lt;BR /&gt;
script = &amp;amp; "$SplunkHome\etc\apps\TA-DomainController-2012R2\bin\Invoke-MonitoredScript.ps1" -Command ".\ad-health.ps1"&lt;BR /&gt;
schedule = 0 */5 * ? * *&lt;BR /&gt;
index = msad&lt;BR /&gt;
source=Powershell&lt;BR /&gt;
sourcetype=MSAD:NT6:Health&lt;BR /&gt;
disabled=false&lt;/P&gt;

&lt;P&gt;ParentIdentity="5e1ba9e1-f102-4156-8e0e-7abed0a5d1c3" ErrorIndex="0" ErrorMessage="A local error has occurred" PositionMessage="At C:\Program Files\SplunkUniversalForwarder\etc\apps\TA-DomainController-2012R2\bin\siteinfo.ps1:7 char:8 + $DC = Get-ADDomainController -Identity $ServerName + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~" CategoryInfo="NotSpecified: (&lt;STRONG&gt;REDACTED&lt;/STRONG&gt;:ADDomainController) [Get-ADDomainController], ADException" FullyQualifiedErrorId="ActiveDirectoryServer:8251,Microsoft.ActiveDirectory.Management.Commands.GetADDomainController" Exception="Microsoft.ActiveDirectory.Management.ADException: A local error has occurred ---&amp;gt; System.ServiceModel.FaultException&lt;CODE&gt;1[schemas.microsoft.com._2008._1.ActiveDirectory.CustomActions.GetADDomainControllerFault]: The lightweight directory access protocol (LDAP) operation failed. Server stack trace: at System.ServiceModel.Channels.ServiceChannel.HandleReply(ProxyOperationRuntime operation, ProxyRpc&amp;amp; rpc) at System.ServiceModel.Channels.ServiceChannel.Call(String action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[] outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage message) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&amp;amp; msgData, Int32 type) at schemas.microsoft.com._2008._1.ActiveDirectory.CustomActions.TopologyManagement.GetADDomainController(GetADDomainControllerRequest request) at Microsoft.ActiveDirectory.Management.AdwsConnection.GetADDomainController(GetADDomainControllerRequest request) --- End of inner exception stack trace --- at Microsoft.ActiveDirectory.Management.AdwsConnection.ThrowException(CustomActionFault caFault, FaultException faultException) at Microsoft.ActiveDirectory.Management.AdwsConnection.GetADDomainController(GetADDomainControllerRequest request) at Microsoft.ActiveDirectory.Management.ADWebServiceStoreAccess.Microsoft.ActiveDirectory.Management.IADTopologyManagement.GetADDomainController(ADSessionHandle handle, GetADDomainControllerRequest request) at Microsoft.ActiveDirectory.Management.ADTopologyManagement.GetDomainController(String[] dcNtdsSettingsDN) at Microsoft.ActiveDirectory.Management.Commands.ADDomainControllerFactory&lt;/CODE&gt;1.GetExtendedObjectFromIdentity(T identityObj, String identityQueryPath, ICollection&lt;CODE&gt;1 propertiesToFetch, Boolean showDeleted) at Microsoft.ActiveDirectory.Management.Commands.ADGetCmdletBase&lt;/CODE&gt;3.ADGetCmdletBaseProcessCSRoutine() at Microsoft.ActiveDirectory.Management.CmdletSubroutinePipeline.Invoke() at Microsoft.ActiveDirectory.Management.Commands.ADCmdletBase&lt;CODE&gt;1.ProcessRecord()" InnerException="System.ServiceModel.FaultException&lt;/CODE&gt;1[schemas.microsoft.com._2008._1.ActiveDirectory.CustomActions.GetADDomainControllerFault]: The lightweight directory access protocol (LDAP) operation failed. (Fault Detail is equal to schemas.microsoft.com._2008._1.ActiveDirectory.CustomActions.GetADDomainControllerFault)."&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:22:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190162#M19378</guid>
      <dc:creator>africates</dc:creator>
      <dc:date>2020-09-28T17:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure - deployment issues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190163#M19379</link>
      <description>&lt;P&gt;Hi africates,&lt;BR /&gt;
Did you verify your ldap.conf?... &lt;BR /&gt;
The following can also help&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/MSApp/1.0.2/MSInfra/EnableAuditingandPowerShellondomaincontrollers"&gt;http://docs.splunk.com/Documentation/MSApp/1.0.2/MSInfra/EnableAuditingandPowerShellondomaincontrollers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2014 15:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190163#M19379</guid>
      <dc:creator>Yasaswy</dc:creator>
      <dc:date>2014-08-21T15:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure - deployment issues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190164#M19380</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I had configured ldap.conf on the Splunk server (\&lt;SERVER&gt;\c$\Program Files\Splunk\etc\apps\SA-ldapsearch\local\ldap.conf) - see the config below.&lt;/SERVER&gt;&lt;/P&gt;

&lt;P&gt;I also enabled auditing and Powershell script execution on AD servers via GPO.&lt;/P&gt;

&lt;P&gt;The only thing which I skipped from the whole installation guide was setting up AD user for Splunk server. Instead of that I am running Splunk server service as domain administrator temporarily which I believe should be fine.&lt;/P&gt;

&lt;P&gt;Any other ideas? Maybee there is some way of debugging the whole process?&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
server = &lt;IP1&gt;&lt;/IP1&gt;&lt;/P&gt;

&lt;P&gt;[my-domain.local]&lt;BR /&gt;
server = &lt;IP1&gt;;&lt;IP2&gt;&lt;BR /&gt;
basedn = DC=my-domain,DC=local&lt;BR /&gt;
binddn = cn=user,OU=Managed Service Accounts,DC=my-domain,DC=local&lt;BR /&gt;
password = xxx&lt;BR /&gt;
alternatedomain = MY-DOMAIN&lt;/IP2&gt;&lt;/IP1&gt;&lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
p&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2014 08:18:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190164#M19380</guid>
      <dc:creator>africates</dc:creator>
      <dc:date>2014-08-22T08:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure - deployment issues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190165#M19381</link>
      <description>&lt;P&gt;OK, I think I'm getting somewhere.. I am able to run 'ldapsearch' using Splunk Support - LDAP Commands app. I can also see some indexes triggered by add-ons installed on DC (i.e. for TA-DomainController-2012R2 when executing: index=msad sourcetype=MSAD:NT6:Health).&lt;BR /&gt;
I still however have problem with Splunk App for Windows Infrastructure. When I'm running 'App Configuration' I'm not getting: Users, Computers and Groups. &lt;BR /&gt;
I was under impression that these are preconfigured in addons which I installed on the DCs but maybe these are not. What I should chec in inputs.conf? thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2014 09:30:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190165#M19381</guid>
      <dc:creator>africates</dc:creator>
      <dc:date>2014-08-22T09:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure - deployment issues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190166#M19382</link>
      <description>&lt;P&gt;I ignored that Users, Computers and Groups weren't detected and checked these under 'App Configuration' &amp;amp; created lookups. I can see some reports when I do the search now but i.e. below (+more) are missing:&lt;BR /&gt;
Users&amp;gt;Administrator Audit (Account Domain and Administrator - no results)&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2014 10:15:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-deployment-issues/m-p/190166#M19382</guid>
      <dc:creator>africates</dc:creator>
      <dc:date>2014-08-22T10:15:56Z</dc:date>
    </item>
  </channel>
</rss>

