<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: issues with splunk app for active directory in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91973#M6176</link>
    <description>&lt;P&gt;I'm getting the same issue as stating in this post.  Can someone help me?  &lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2014 12:39:03 GMT</pubDate>
    <dc:creator>eljaybee</dc:creator>
    <dc:date>2014-02-14T12:39:03Z</dc:date>
    <item>
      <title>issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91963#M6166</link>
      <description>&lt;P&gt;I cant seem to run any reports within the splunk app for active directory.&lt;/P&gt;

&lt;P&gt;For instance if I run user logon failures i get "Lookup table 'HostInfo' is empty."&lt;/P&gt;

&lt;P&gt;Administrator audit:  I get Lookup table 'HostInfo' is empty. and Lookup table 'tSessions' is empty.&lt;/P&gt;

&lt;P&gt;Any help is appreciated since I am trying to set this up to present prior to purchasing.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 17:03:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91963#M6166</guid>
      <dc:creator>freeborn</dc:creator>
      <dc:date>2012-07-05T17:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91964#M6167</link>
      <description>&lt;P&gt;The tHostInfo and tSessions tables are generated by saved searches that run on a five minute schedule.  There are a couple of reasons why they would not be shown:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;You have not turned on Audit on all your domains as described in the setup documentation&lt;/LI&gt;
&lt;LI&gt;You are running Admin Audit with a search period that is less than five minutes&lt;/LI&gt;
&lt;LI&gt;You have a more complex environment and your saved searches are not generating the files in the right place (unlikely if you are using the free version - this is more common in complex multi-search-head environments)&lt;/LI&gt;
&lt;LI&gt;For some reason, the saved search is not firing (also uncommon)&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I suspect #1 is the culprit.  If you don't enable audit, then successful logons don't get recorded, and the tSessions and tHostInfo look ups will be empty as a result of no events.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 18:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91964#M6167</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-07-05T18:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91965#M6168</link>
      <description>&lt;OL&gt;
&lt;LI&gt;- I did and I have confirmed&lt;/LI&gt;
&lt;LI&gt;not sure what you mean (trying my search for a 24hr period if thats what you mean)&lt;/LI&gt;
&lt;LI&gt;not the case&lt;/LI&gt;
&lt;LI&gt;Possible this is it but I dont know how to verify&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 18:37:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91965#M6168</guid>
      <dc:creator>freeborn</dc:creator>
      <dc:date>2012-07-05T18:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91966#M6169</link>
      <description>&lt;P&gt;I've just had another report of the tHostInfo table being broken, and I am investigating.  It doesn't happen on my system, so any information you can provide on your AD environment would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2012 19:02:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91966#M6169</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-07-05T19:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91967#M6170</link>
      <description>&lt;P&gt;Ahall_splunk...if you would like to have a look at my install...let me know.  Our temp license runs to July 20th and I am trying to prove a POC to purchase.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2012 13:56:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91967#M6170</guid>
      <dc:creator>freeborn</dc:creator>
      <dc:date>2012-07-09T13:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91968#M6171</link>
      <description>&lt;P&gt;Get in touch with your Splunk sales team and ask them to get me involved.  We'll get something sorted.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2012 14:05:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91968#M6171</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-07-09T14:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91969#M6172</link>
      <description>&lt;P&gt;Adrian, was there a solution to this problem? I am also having the same issue. I did verify also that my auditing matches the documentation.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2012 03:42:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91969#M6172</guid>
      <dc:creator>lfcowart</dc:creator>
      <dc:date>2012-09-05T03:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91970#M6173</link>
      <description>&lt;P&gt;I have yet to be involved in this particular request.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2012 16:20:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91970#M6173</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-09-05T16:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91971#M6174</link>
      <description>&lt;P&gt;hi, I'm getting the same error too but no solution yet. Could anyone share? &lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2012 06:15:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91971#M6174</guid>
      <dc:creator>kelvinlow</dc:creator>
      <dc:date>2012-10-02T06:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91972#M6175</link>
      <description>&lt;P&gt;Please open up a new issue / answers - your situation may be different.  Don't forget to include what version of the app you are running, what version of windows, what version of splunk, etc.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2012 14:23:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91972#M6175</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-10-02T14:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: issues with splunk app for active directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91973#M6176</link>
      <description>&lt;P&gt;I'm getting the same issue as stating in this post.  Can someone help me?  &lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2014 12:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/issues-with-splunk-app-for-active-directory/m-p/91973#M6176</guid>
      <dc:creator>eljaybee</dc:creator>
      <dc:date>2014-02-14T12:39:03Z</dc:date>
    </item>
  </channel>
</rss>

