<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk App for Windows Infrastructure AD issue in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121499#M9366</link>
    <description>&lt;P&gt;I'm trying to get the Splunk App for Windows Infrastructure working (works for windows events but nothing else) and I'm running into some problems with AD. I believe I have everything setup correctly. I can search AD, for example, |ldapsearch domain=DOMAIN search="(cn=Administrator)" returns a result. However, when I do this search eventtype=msad-dc-health it returns nothing. And when I try to run one of the macros, like &lt;CODE&gt;domain-list&lt;/CODE&gt;|dedup host|outputlookup DomainList.csv, it returns Error in 'SearchParser': Could not find macro 'domain-list' that takes 0 arguments. Expecting stanza name 'domain-list'. What am I doing wrong? I've also tried the legacy AD app without success. All the prerequisites appear to be met. Nothing ever populates in the apps AD queries. Thanks.&lt;/P&gt;</description>
    <pubDate>Sun, 06 Apr 2014 20:10:13 GMT</pubDate>
    <dc:creator>zwillis24</dc:creator>
    <dc:date>2014-04-06T20:10:13Z</dc:date>
    <item>
      <title>Splunk App for Windows Infrastructure AD issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121499#M9366</link>
      <description>&lt;P&gt;I'm trying to get the Splunk App for Windows Infrastructure working (works for windows events but nothing else) and I'm running into some problems with AD. I believe I have everything setup correctly. I can search AD, for example, |ldapsearch domain=DOMAIN search="(cn=Administrator)" returns a result. However, when I do this search eventtype=msad-dc-health it returns nothing. And when I try to run one of the macros, like &lt;CODE&gt;domain-list&lt;/CODE&gt;|dedup host|outputlookup DomainList.csv, it returns Error in 'SearchParser': Could not find macro 'domain-list' that takes 0 arguments. Expecting stanza name 'domain-list'. What am I doing wrong? I've also tried the legacy AD app without success. All the prerequisites appear to be met. Nothing ever populates in the apps AD queries. Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Apr 2014 20:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121499#M9366</guid>
      <dc:creator>zwillis24</dc:creator>
      <dc:date>2014-04-06T20:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure AD issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121500#M9367</link>
      <description>&lt;P&gt;Have you deployed the TAs for active directory monitoring?&lt;/P&gt;

&lt;P&gt;Specifically:  TA-DNSServer-NT5  TA-DNSServer-NT6  TA-DomainController-2012R2  TA-DomainController-NT5  TA-DomainController-NT6  (as appropriate)&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 20:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121500#M9367</guid>
      <dc:creator>dbylertbg</dc:creator>
      <dc:date>2014-04-11T20:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure AD issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121501#M9368</link>
      <description>&lt;P&gt;Thanks for the reply. I do have those setup in local folders... I think correctly. Any reason why I would be getting this error Error in 'SearchParser': Could not find macro 'domain-list' that takes 0 arguments. Or anything else you can think of that I might be missing? I went through the setup docs very closely. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 22:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121501#M9368</guid>
      <dc:creator>zwillis24</dc:creator>
      <dc:date>2014-04-11T22:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure AD issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121502#M9369</link>
      <description>&lt;P&gt;have you verified your ldapsearch is working properly?  Specifically the SA-ldapsearch addon required?   &lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 12:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121502#M9369</guid>
      <dc:creator>dwithers</dc:creator>
      <dc:date>2014-04-16T12:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure AD issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121503#M9370</link>
      <description>&lt;P&gt;I did. That is working fine. I can search AD and AD changes are being indexed.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 18:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121503#M9370</guid>
      <dc:creator>zwillis24</dc:creator>
      <dc:date>2014-04-16T18:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure AD issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121504#M9371</link>
      <description>&lt;P&gt;Fix by Splunk support. There was an issue with the newest version of the Active Directory app.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2014 09:35:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Windows-Infrastructure-AD-issue/m-p/121504#M9371</guid>
      <dc:creator>zwillis78</dc:creator>
      <dc:date>2014-04-24T09:35:50Z</dc:date>
    </item>
  </channel>
</rss>

