<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Infrastructure app - Active Directory Error in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Infrastructure-app-Active-Directory-Error/m-p/531821#M64359</link>
    <description>&lt;P&gt;Possible explanation &lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Windows-Infrastructure-can-t-track-AD-Users-or-Groups/m-p/193476/highlight/false#M19906" target="_self"&gt;here&lt;/A&gt;. Few years old though. The suggestion is that the detect features check only looks for events in the last 15min. So click enable on the 'not found' features, and save.&lt;/P&gt;&lt;P&gt;The Windows Infrastructure dashboards should start populating data given enough time.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2020 06:31:52 GMT</pubDate>
    <dc:creator>Ibbers</dc:creator>
    <dc:date>2020-12-03T06:31:52Z</dc:date>
    <item>
      <title>Windows Infrastructure app - Active Directory Error</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Infrastructure-app-Active-Directory-Error/m-p/467923#M57496</link>
      <description>&lt;P&gt;Hello Spunkers,&lt;BR /&gt;
I have Splunk app for Windows Infrastructure installed and have done the setup but when I get to the "customize features" section it can't find the AD data it is looking for. The Windows Overview dashboard is populating and it is finding some AD data, so I think the AD data is being ingested just not being parsed correctly, but I don't know how to tell.&lt;BR /&gt;
Thanks in advance for any help.&lt;/P&gt;

&lt;P&gt;Here is the output of the "detect features" button.&lt;BR /&gt;
Detecting Event Monitoring ...&lt;BR /&gt;
Windows: Event Monitoring found.&lt;BR /&gt;
Detecting Performance Monitoring ...&lt;BR /&gt;
Windows: Performance Monitoring found.&lt;BR /&gt;
Detecting Applications and Updates ...&lt;BR /&gt;
Windows: Applications and Updates found.&lt;BR /&gt;
Detecting Network Monitoring ...&lt;BR /&gt;
Windows: Network Monitoring not found.  (This one is expected)&lt;BR /&gt;
Detecting Print Monitoring ...&lt;BR /&gt;
Windows: Print Monitoring not found.  (This one is expected)&lt;BR /&gt;
Detecting Host Monitoring ...&lt;BR /&gt;
Windows: Host Monitoring found.&lt;BR /&gt;
Detecting Domains ...&lt;BR /&gt;
Active Directory: Domains not found.&lt;BR /&gt;
Detecting Domain Controllers ...&lt;BR /&gt;
Active Directory: Domain Controllers not found.&lt;BR /&gt;
Detecting DNS ...&lt;BR /&gt;
Active Directory: DNS found.&lt;BR /&gt;
Detecting Users ...&lt;BR /&gt;
Active Directory: Users not found.&lt;BR /&gt;
Detecting Computers ...&lt;BR /&gt;
Active Directory: Computers not found.&lt;BR /&gt;
Detecting Groups ...&lt;BR /&gt;
Active Directory: Groups not found.&lt;BR /&gt;
Detecting Group Policy ...&lt;BR /&gt;
Active Directory: Group Policy found.&lt;BR /&gt;
Detecting Organizational Units ...&lt;BR /&gt;
Active Directory: Organizational Units found.&lt;/P&gt;

&lt;P&gt;Splunk version: 7.3.0&lt;BR /&gt;
Splunk app for Windows Infrastructure version: 2.0.1&lt;BR /&gt;
Splunk Supporting Add-on for Active Directory version: 3.0.1  (Connection status on configuration tab is successful)&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 19:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Infrastructure-app-Active-Directory-Error/m-p/467923#M57496</guid>
      <dc:creator>eliasit</dc:creator>
      <dc:date>2020-04-07T19:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Infrastructure app - Active Directory Error</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Infrastructure-app-Active-Directory-Error/m-p/531818#M64357</link>
      <description>&lt;P&gt;How did you end up going with this? I've had a similiar thing (Perfmon and Printmon were expected for me, as I'd disabled the inputs) with my setup.&lt;BR /&gt;&lt;BR /&gt;I haven't found much in the way of explanation unfortunately in doco, beyond a vague suggestion that the feature/s may not work if Active Directory hasn't generated the logs on its end.&lt;BR /&gt;&lt;BR /&gt;Sidenote - did you do anything to get the Applications and Updates detected?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 06:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Infrastructure-app-Active-Directory-Error/m-p/531818#M64357</guid>
      <dc:creator>Ibbers</dc:creator>
      <dc:date>2020-12-03T06:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Infrastructure app - Active Directory Error</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Infrastructure-app-Active-Directory-Error/m-p/531821#M64359</link>
      <description>&lt;P&gt;Possible explanation &lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/App-for-Windows-Infrastructure-can-t-track-AD-Users-or-Groups/m-p/193476/highlight/false#M19906" target="_self"&gt;here&lt;/A&gt;. Few years old though. The suggestion is that the detect features check only looks for events in the last 15min. So click enable on the 'not found' features, and save.&lt;/P&gt;&lt;P&gt;The Windows Infrastructure dashboards should start populating data given enough time.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 06:31:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Infrastructure-app-Active-Directory-Error/m-p/531821#M64359</guid>
      <dc:creator>Ibbers</dc:creator>
      <dc:date>2020-12-03T06:31:52Z</dc:date>
    </item>
  </channel>
</rss>

