<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lookup problem with ms windows ad project in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586997#M76241</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i c'ant fin&amp;nbsp;&lt;SPAN&gt;ms_ad_obj_wrkaround_msad_action on&amp;nbsp;&lt;A href="http://127.0.0.1:8000/en-US/manager/launcher/data/transforms/lookups" target="_blank"&gt;Lookup definitions&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Mar 2022 13:09:14 GMT</pubDate>
    <dc:creator>hichem_khalfi</dc:creator>
    <dc:date>2022-03-01T13:09:14Z</dc:date>
    <item>
      <title>Need help with lookup problem with ms windows ad project</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586986#M76237</link>
      <description>&lt;P&gt;I'm new with splunk, I installed app ms windows ad object but in order to fix the shared points:&lt;BR /&gt;First: Add an automatic lookup for source XMLWinEventLog:Security using the AD_Audit_Change_EventCodes lookup.&lt;BR /&gt;In the MS Windows AD Objects app, navigate to Settings - - &amp;gt; Lookups - - &amp;gt; Automatic Lookups.&lt;BR /&gt;Click New Automatic Lookup&lt;BR /&gt;Enter the following:&lt;BR /&gt;Name: ms_ad_obj_wrkaround_msad_action&lt;BR /&gt;Source: XmlWinEventLog:Security&lt;BR /&gt;Lookup Input Fields:&lt;BR /&gt;EventCode = EventCode&lt;BR /&gt;obj_type = obj_type&lt;BR /&gt;Lookup output Fields:&lt;BR /&gt;change_action = change_action&lt;BR /&gt;Click Save&lt;BR /&gt;Set the permissions to the app and role permissions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did what is asked but I still get the message:&lt;BR /&gt;Could not load lookup=LOOKUP-ms_ad_obj_wrkaround_msad_action&lt;/P&gt;
&lt;P&gt;with a failure for some functionalities of the application&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 16:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586986#M76237</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-03-01T16:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: lookup problem with ms windows ad project</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586989#M76238</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't love automatic lookups because sometimes they don't work and anyway it's more difficoult to debug code when there's a problem.&lt;/P&gt;&lt;P&gt;Anyway, before to create an automatic lookup, you have to create a lookup and test it; automatic lookup is only a rule but it doesn't create the lookup.&lt;/P&gt;&lt;P&gt;Did you cretead the lookup and the lookup definition?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 12:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586989#M76238</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-01T12:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: lookup problem with ms windows ad project</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586991#M76239</link>
      <description>&lt;P&gt;no, i did what the app owners asked&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 12:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586991#M76239</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-03-01T12:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: lookup problem with ms windows ad project</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586995#M76240</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Ok check if the lookup and the lookup definition of &lt;SPAN&gt;ms_ad_obj_wrkaround_msad_action&amp;nbsp;&lt;/SPAN&gt;are defined or not.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 13:01:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586995#M76240</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-01T13:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: lookup problem with ms windows ad project</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586997#M76241</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i c'ant fin&amp;nbsp;&lt;SPAN&gt;ms_ad_obj_wrkaround_msad_action on&amp;nbsp;&lt;A href="http://127.0.0.1:8000/en-US/manager/launcher/data/transforms/lookups" target="_blank"&gt;Lookup definitions&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 13:09:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586997#M76241</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-03-01T13:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: lookup problem with ms windows ad project</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586999#M76242</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, the problem is that you want to create an automatic lookup without create lookup and lookup definition before.&lt;/P&gt;&lt;P&gt;Check the documentation.&lt;/P&gt;&lt;P&gt;Maybe you are only using a wrong name.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 13:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/586999#M76242</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-01T13:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: lookup problem with ms windows ad project</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/587003#M76243</link>
      <description>&lt;P&gt;please read:&amp;nbsp; &amp;nbsp;that what i did exactly , i havent LOOKUP-ms_ad_obj_wrkaround_msad_action from the begin and i create it as the app owner told&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H2&gt;IMPORTANT - XMLWinEventLog - msad_action field extraction - Work Around&lt;/H2&gt;&lt;P&gt;There is a current issue where the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;msad_action&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field is not being extracted by the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Splunk AddOn for Windows&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for XMLWinEventLogs. This field is heavily leveraged by this application, so below is a workaround until the TA is fixed, or a new version of this app is released.&lt;/P&gt;&lt;H3&gt;&lt;I&gt;First:&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Add an automatic lookup for source XMLWinEventLog:Security using the AD_Audit_Change_EventCodes lookup.&lt;/H3&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In the MS Windows AD Objects app, navigate to Settings - - &amp;gt; Lookups - - &amp;gt; Automatic Lookups.&lt;/LI&gt;&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;New Automatic Lookup&lt;/I&gt;&lt;/LI&gt;&lt;LI&gt;Enter the following:&lt;UL&gt;&lt;LI&gt;&lt;I&gt;Name:&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;ms_ad_obj_wrkaround_msad_action&lt;/LI&gt;&lt;LI&gt;&lt;I&gt;Source:&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;XmlWinEventLog:Security&lt;/LI&gt;&lt;LI&gt;&lt;I&gt;Lookup Input Fields:&lt;/I&gt;&lt;UL&gt;&lt;LI&gt;EventCode = EventCode&lt;/LI&gt;&lt;LI&gt;obj_type = obj_type&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;I&gt;Lookup output Fields:&lt;/I&gt;&lt;UL&gt;&lt;LI&gt;change_action = change_action&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Save&lt;/I&gt;&lt;/LI&gt;&lt;LI&gt;Set the permissions to the app and role permissions&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;I&gt;Second:&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Update the source::XmlWinEventLog:Security : EVAL-msad_action calculated field in the MS Windows AD Objects app.&lt;/H3&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In the MS Windows AD Objects app, navigate to Settings - - &amp;gt; Fields - - &amp;gt; Calculated Fields&lt;/LI&gt;&lt;LI&gt;In the Search box, type&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;msad_action&lt;/I&gt;&lt;/LI&gt;&lt;LI&gt;Click on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;source::XmlWinEventLog:Security : EVAL-msad_action&lt;/I&gt;&lt;/LI&gt;&lt;LI&gt;Replace the Eval Expression:&lt;UL&gt;&lt;LI&gt;&lt;I&gt;From:&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;if(msad_action=“change” OR msad_action=“changed” OR msad_action=“set” OR msad_action=“reset”,“modified”,if(msad_action=“add”,“added”,if(EventID=“4722",“enabled”,msad_action)))&lt;/LI&gt;&lt;LI&gt;&lt;I&gt;To:&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;if(isnull(change_action),if(msad_action=“change” OR msad_action=“changed” OR msad_action=“set” OR msad_action=“reset”,“modified”,if(msad_action=“add”,“added”,if(EventID=“4722”,“enabled”,msad_action))),change_action)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Save&lt;/I&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 01 Mar 2022 13:35:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/587003#M76243</guid>
      <dc:creator>hichem_khalfi</dc:creator>
      <dc:date>2022-03-01T13:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: lookup problem with ms windows ad project</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/587030#M76244</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242707"&gt;@hichem_khalfi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I haven't this app so I cannot test it, but the instruction seems to be clear:&amp;nbsp;&lt;/P&gt;&lt;P&gt;did you created the Automatic Lookup and the calculated field in the same App or outside it?&lt;/P&gt;&lt;P&gt;did you give the grants to the automatic lookup and the calculated field?&lt;/P&gt;&lt;P&gt;If you don't reach to solve the problem, you can contact the developer (there's a link in&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3177/" target="_blank"&gt;https://splunkbase.splunk.com/app/3177/&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 15:06:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Need-help-with-lookup-problem-with-ms-windows-ad-project/m-p/587030#M76244</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-01T15:06:27Z</dc:date>
    </item>
  </channel>
</rss>

