<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does the Splunk App for Windows Infrastructure not show any User, Computer, or Group data? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216912#M23510</link>
    <description>&lt;P&gt;usually:&lt;BR /&gt;
 -  index permission, you can check in your role if you can search the specific windows indexes by default, or make sure you inherit for a role that can.&lt;BR /&gt;
 - and also some dashboards have a dependency with the ldap search addon (SA-Ldapsearch), to talk to your AD server.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Jan 2016 18:52:19 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2016-01-10T18:52:19Z</dc:date>
    <item>
      <title>Why does the Splunk App for Windows Infrastructure not show any User, Computer, or Group data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216908#M23506</link>
      <description>&lt;P&gt;We are running the following versions of Splunk and supporting apps for Windows infrastructure:&lt;/P&gt;

&lt;P&gt;Splunk Enterprise 6.3.2&lt;BR /&gt;
Splunk App for Windows Infrastructure 1.2.0&lt;BR /&gt;
Splunk Supporting Add-on for Active Directory 2.1.2&lt;BR /&gt;
Windows Add-on 4.8.1&lt;BR /&gt;
German OS&lt;/P&gt;

&lt;P&gt;The Splunk App for Windows Infrastructure does not Show me any User, Computer, or Group entry.&lt;BR /&gt;
Also the Guided Setup says "users not found", and "Groups not found", but "Computers found"&lt;BR /&gt;
Also no OU is displayed in the Org Units: All Dashboard&lt;/P&gt;

&lt;P&gt;On the DC the following apps are installed:&lt;BR /&gt;
SA-ModularInput-PowerShell&lt;BR /&gt;
sendtoindexer&lt;BR /&gt;
Splunk_TA_windows&lt;BR /&gt;
TA-DNSServer-NT6&lt;BR /&gt;
TA-DomainController-2012R2&lt;/P&gt;

&lt;P&gt;Because I am totally new to Splunk, please can someone help me to figure out why I can't get data?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216908#M23506</guid>
      <dc:creator>ugruner</dc:creator>
      <dc:date>2020-09-29T08:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk App for Windows Infrastructure not show any User, Computer, or Group data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216909#M23507</link>
      <description>&lt;P&gt;Within the search app, do you see any data at all related to these sourcetypes? That is, if you go to apps -&amp;gt; search and reporting -&amp;gt; search for &lt;CODE&gt;"*"&lt;/CODE&gt;, do you see any results? If not, if you change your search to &lt;CODE&gt;index=*&lt;/CODE&gt;, do you see any data?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2016 00:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216909#M23507</guid>
      <dc:creator>sobrien</dc:creator>
      <dc:date>2016-01-08T00:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk App for Windows Infrastructure not show any User, Computer, or Group data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216910#M23508</link>
      <description>&lt;P&gt;index=msad" Shows a lot of data &lt;BR /&gt;
source=ActiveDirectory also exists with thousands of data.&lt;/P&gt;

&lt;P&gt;I can use the Splunk App for Windows Infrastructure and browse all data e.g DNS, Domain Status, Health Status, only those for User, Groups, OU and Computers have no data if I open the Dashboards.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2016 07:20:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216910#M23508</guid>
      <dc:creator>ugruner</dc:creator>
      <dc:date>2016-01-08T07:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk App for Windows Infrastructure not show any User, Computer, or Group data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216911#M23509</link>
      <description>&lt;P&gt;I see. Those dashboards require SA-Ldapsearch to populate. Can you confirm if you have that installed and configured? &lt;A href="https://splunkbase.splunk.com/app/1151/"&gt;https://splunkbase.splunk.com/app/1151/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2016 21:19:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216911#M23509</guid>
      <dc:creator>sobrien</dc:creator>
      <dc:date>2016-01-09T21:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk App for Windows Infrastructure not show any User, Computer, or Group data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216912#M23510</link>
      <description>&lt;P&gt;usually:&lt;BR /&gt;
 -  index permission, you can check in your role if you can search the specific windows indexes by default, or make sure you inherit for a role that can.&lt;BR /&gt;
 - and also some dashboards have a dependency with the ldap search addon (SA-Ldapsearch), to talk to your AD server.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2016 18:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216912#M23510</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2016-01-10T18:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk App for Windows Infrastructure not show any User, Computer, or Group data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216913#M23511</link>
      <description>&lt;P&gt;severals issues:&lt;BR /&gt;
SA-Ldapsearch was configured but not in the way App for Windows Infrastructure needs it to work correctly.&lt;BR /&gt;
The "default" stanza must be filled out and a second stanza with the FQDN must exists. The Alternative name in both stanzas must be the same. The Wizard detects duplicates, so one Alternative Name should be written in UPPERCASES and one in lowercases. &lt;BR /&gt;
Last but not least if you running splunk Server on german OS, you don't see data in some Dashboards. So I have to Switch to English OS for the splunk Server. After this ALL Dashboards Shows up Information. To make it clear Data was sent to the Indexes but the Dashboards could not display those.&lt;BR /&gt;
Also the Eventlogs from non english Servers should be sent as XML.&lt;BR /&gt;
&lt;A href="http://blogs.splunk.com/2014/11/04/splunk-6-2-feature-overview-xml-event-logs/"&gt;http://blogs.splunk.com/2014/11/04/splunk-6-2-feature-overview-xml-event-logs/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 14:03:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216913#M23511</guid>
      <dc:creator>ugruner</dc:creator>
      <dc:date>2016-01-14T14:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk App for Windows Infrastructure not show any User, Computer, or Group data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216914#M23512</link>
      <description>&lt;P&gt;please transform your comment to an answer and accept it as answer! This is really helpful!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 16:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-App-for-Windows-Infrastructure-not-show-any/m-p/216914#M23512</guid>
      <dc:creator>PPape</dc:creator>
      <dc:date>2016-01-18T16:50:17Z</dc:date>
    </item>
  </channel>
</rss>

