<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD overview, Windows Overview - no data in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/AD-overview-Windows-Overview-no-data/m-p/451782#M24142</link>
    <description>&lt;P&gt;Hello skalliger,&lt;/P&gt;

&lt;P&gt;Thanks for the reply. I ended up re-installing the app. And many of the issues are gone now.&lt;BR /&gt;
I have not yet  re-installed the Windows Infrastructure or the Windows app for AD as yet.&lt;BR /&gt;
 We are not using the UF on any of the Windows boxes. &lt;/P&gt;

&lt;P&gt;We are using WMI to query the logs. The version of splunk is 7.3.1 and it runs as a domain user (for WMI access), and the user is also in the local users on the splunk server/indexer.&lt;/P&gt;

&lt;P&gt;I think that I have discovered the problem as far as the event logs, etc. Currently the machines that are being monitored via WMI are storing their logs in the "default" index. If I decide to re-install the apps - the indexes will have to be changed as appropriate: like "winevents" or "windowslogs" etc.&lt;/P&gt;

&lt;P&gt;Thanks Again,&lt;BR /&gt;
Eholz1&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2019 15:13:08 GMT</pubDate>
    <dc:creator>eholz1</dc:creator>
    <dc:date>2019-08-16T15:13:08Z</dc:date>
    <item>
      <title>AD overview, Windows Overview - no data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/AD-overview-Windows-Overview-no-data/m-p/451780#M24140</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;
I am using splunk Enterprise 7.3.1, with the windows apps and the AD add-on for windows AD.&lt;BR /&gt;
I get no data in the Windows Overview or the AD overview. There is no current data in the wineventlog and no data in the winevents log. I have used the inputs.conf file as mentioned in the splunk documentation here: &lt;BR /&gt;
docs.splunk.com/Documentation/MSApp/1.5.2/MSInfra/DownloadandconfiguretheSplunkAdd-onforWindowsversion6.0.0orlater&lt;/P&gt;

&lt;P&gt;I have inputs.conf files in etc\system\local and app\splunk_TA_windows\local&lt;BR /&gt;
and wmi.conf file in etc\system\local&lt;/P&gt;

&lt;P&gt;What am I missing in the configuration?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
eholz1&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/AD-overview-Windows-Overview-no-data/m-p/451780#M24140</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2020-09-30T01:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: AD overview, Windows Overview - no data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/AD-overview-Windows-Overview-no-data/m-p/451781#M24141</link>
      <description>&lt;P&gt;Did you deploy the Windows TA to a Universal Forwarder? Is the UF running as a domain account or LOCAL SYSTEM?&lt;BR /&gt;
Does the UF send any data at all? Look for the host in &lt;CODE&gt;index=_internal&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 09:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/AD-overview-Windows-Overview-no-data/m-p/451781#M24141</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-08-16T09:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: AD overview, Windows Overview - no data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/AD-overview-Windows-Overview-no-data/m-p/451782#M24142</link>
      <description>&lt;P&gt;Hello skalliger,&lt;/P&gt;

&lt;P&gt;Thanks for the reply. I ended up re-installing the app. And many of the issues are gone now.&lt;BR /&gt;
I have not yet  re-installed the Windows Infrastructure or the Windows app for AD as yet.&lt;BR /&gt;
 We are not using the UF on any of the Windows boxes. &lt;/P&gt;

&lt;P&gt;We are using WMI to query the logs. The version of splunk is 7.3.1 and it runs as a domain user (for WMI access), and the user is also in the local users on the splunk server/indexer.&lt;/P&gt;

&lt;P&gt;I think that I have discovered the problem as far as the event logs, etc. Currently the machines that are being monitored via WMI are storing their logs in the "default" index. If I decide to re-install the apps - the indexes will have to be changed as appropriate: like "winevents" or "windowslogs" etc.&lt;/P&gt;

&lt;P&gt;Thanks Again,&lt;BR /&gt;
Eholz1&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 15:13:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/AD-overview-Windows-Overview-no-data/m-p/451782#M24142</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-08-16T15:13:08Z</dc:date>
    </item>
  </channel>
</rss>

