<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble Setting Up Splunk App for Active Directory in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23497#M628</link>
    <description>&lt;P&gt;Thanks for the suggestions. I can confirm that no firewall is turned on for either the UF or Indexer. The receiver has been setup on the indexer on port 9997, and from what I can see on the UF there does not appear to be traffic transmitting on that port.&lt;/P&gt;

&lt;P&gt;I will post my outputs.conf file in another comment. If you could take a look and let me know if you notice anything off about it, I would appreciate it.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Nov 2012 20:20:15 GMT</pubDate>
    <dc:creator>jakob2534</dc:creator>
    <dc:date>2012-11-05T20:20:15Z</dc:date>
    <item>
      <title>Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23490#M621</link>
      <description>&lt;P&gt;I have setup the free version of Splunk and installed the Splunk App for Active Directory. I am trying to pilot a POC to our IT leadership with hopes to budget for and purchase Enterprise licensing early next year. Unfortunately, I do not seem to be receiving any data from the UF installed on our Domain Controller. I have read through all of the online documentation I can find and followed it to the best of my ability, but I’m assuming I’m missing some critical step or have misconfigured something. We are a single domain, single forest, and are running at a forest/domain functional level of 2003. So far I have:&lt;/P&gt;

&lt;P&gt;• Deployed new Windows Server 2008 R2 Standard, fully patched&lt;/P&gt;

&lt;P&gt;• Installed single Splunk instance as primary deployment server, indexer, and search head&lt;/P&gt;

&lt;P&gt;• Enabled AD Auditing and script execution via GPO&lt;/P&gt;

&lt;P&gt;• Downloaded Splunk App for Active Directory and Splunk TAs for Windows&lt;/P&gt;

&lt;P&gt;• Copied Splunk TA Windows, TA-DomainController-NT6, and TA-DNSServer-NT6 to Splunk\etc\deployment-apps on Splunk server&lt;/P&gt;

&lt;P&gt;• Configured serverclass.conf on deployment server&lt;/P&gt;

&lt;P&gt;• Installed UF on Windows Server 2008 R2 Domain Controller, and configured to point to deployment server on port 8089&lt;/P&gt;

&lt;P&gt;• Installed SA-ldapsearch, Sideview Utils, Splunk App for Active Directory, and Splunk TAs for Windows on Splunk server&lt;/P&gt;

&lt;P&gt;• Configured ldap.conf and eventtypes.conf&lt;/P&gt;

&lt;P&gt;• Restarted Splunk server and UF&lt;/P&gt;

&lt;P&gt;• Confirmed that the UF on the DC received the deployed apps&lt;/P&gt;

&lt;P&gt;I’ve searched the Splunkbase and online documentation, and can’t determine why I’m not receiving any data from the UF. Any help you can provide would be very helpful. Let me know if you need me to provide any sort of logs or config files to better troubleshoot.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 16:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23490#M621</guid>
      <dc:creator>jakob2534</dc:creator>
      <dc:date>2012-11-05T16:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23491#M622</link>
      <description>&lt;P&gt;Have you verified that that your UF is sending any data?  Ccheck _internal look for metrics.log and your UF.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 16:35:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23491#M622</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2012-11-05T16:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23492#M623</link>
      <description>&lt;P&gt;Thanks for the suggestion. I just checked and there are multiple metrics.log logs. So it would appear the UF is at least collecting date, right?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 16:39:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23492#M623</guid>
      <dc:creator>jakob2534</dc:creator>
      <dc:date>2012-11-05T16:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23493#M624</link>
      <description>&lt;P&gt;try this search.  This will tell you if there is any through put coming over your recieving port on your indexer.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
index=_internal source="%splunk%\var\log\splunk\metrics.log" destPort=9997 | bucket _time span=1m | stats sum(tcp_KBps) as thruput by _time, hostname&lt;BR /&gt;
&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:44:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23493#M624</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2020-09-28T12:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23494#M625</link>
      <description>&lt;P&gt;Says: "No results found."&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 16:54:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23494#M625</guid>
      <dc:creator>jakob2534</dc:creator>
      <dc:date>2012-11-05T16:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23495#M626</link>
      <description>&lt;P&gt;If you modified the splunk path to be your specific path then it seems that you have a basic communication issue.  Are there any events for &lt;BR /&gt;
&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
index=_internal source="%splunk%\var\log\splunk\metrics.log" destPort=9997&lt;BR /&gt;
&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;
- Have you configured your Indexer to receive data on port 9997 (default port)?&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Have you configured your UF to forward over port 9997 to your indexer?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Try using portqry.exe from Microsoft to test your ports&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 05 Nov 2012 17:06:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23495#M626</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2012-11-05T17:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23496#M627</link>
      <description>&lt;P&gt;Since nothing is coming across, check these things:&lt;/P&gt;

&lt;P&gt;1) Do you have Windows Firewall turned on for your Splunk Indexer?  If you do, you need to either turn it off or add an exception in for the TCP port you are using to receive data&lt;BR /&gt;
2) Have you set up a Receiver for the UF to indexer data transfer on the Splunk Indexer?&lt;BR /&gt;
3) Do you have an appropriate outputs.conf on your UF&lt;BR /&gt;
4) Do you have a firewall on the UF that prevents you from communicating with the indexer?&lt;/P&gt;

&lt;P&gt;One of those four should get data flowing to the indexer.  Once you have that, everything else should "just work"&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 19:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23496#M627</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-11-05T19:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23497#M628</link>
      <description>&lt;P&gt;Thanks for the suggestions. I can confirm that no firewall is turned on for either the UF or Indexer. The receiver has been setup on the indexer on port 9997, and from what I can see on the UF there does not appear to be traffic transmitting on that port.&lt;/P&gt;

&lt;P&gt;I will post my outputs.conf file in another comment. If you could take a look and let me know if you notice anything off about it, I would appreciate it.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 20:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23497#M628</guid>
      <dc:creator>jakob2534</dc:creator>
      <dc:date>2012-11-05T20:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23498#M629</link>
      <description>&lt;P&gt;[tcpout]&lt;BR /&gt;
autoLB = true&lt;BR /&gt;
maxQueueSize = 500KB&lt;BR /&gt;
forwardedindex.0.whitelist = .*&lt;BR /&gt;
forwardedindex.1.blacklist = _.*&lt;BR /&gt;
forwardedindex.2.whitelist = _audit&lt;BR /&gt;
forwardedindex.filter.disable = false&lt;BR /&gt;
indexAndForward = false&lt;BR /&gt;
autoLBFrequency = 30&lt;BR /&gt;
blockOnCloning = true&lt;BR /&gt;
compressed = false&lt;BR /&gt;
disabled = false&lt;BR /&gt;
dropClonedEventsOnQueueFull = 5&lt;BR /&gt;
dropEventsOnQueueFull = -1&lt;BR /&gt;
heartbeatFrequency = 30&lt;BR /&gt;
maxFailuresPerInterval = 2&lt;BR /&gt;
secsInFailureInterval = 1&lt;BR /&gt;
maxConnectionsPerIndexer = 2&lt;BR /&gt;
sendCookedData = true&lt;BR /&gt;
connectionTimeout = 20 &lt;BR /&gt;
readTimeout = 300&lt;BR /&gt;
writeTimeout = 300 &lt;BR /&gt;
useACK = false&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 20:20:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23498#M629</guid>
      <dc:creator>jakob2534</dc:creator>
      <dc:date>2012-11-05T20:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Setting Up Splunk App for Active Directory</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23499#M630</link>
      <description>&lt;P&gt;If thats the whole of outputs.conf, then there is no IP address of your indexer there.  Take a look at this page:  &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can create a TA-forwarder on your deployment server and push an outputs.conf file out to your forwarder if that piece is working.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 20:53:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-Setting-Up-Splunk-App-for-Active-Directory/m-p/23499#M630</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2012-11-05T20:53:14Z</dc:date>
    </item>
  </channel>
</rss>

