<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MS security integration with splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694360#M115376</link>
    <description>&lt;P&gt;Typical GDI troubleshooting steps include:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Verify the input configuration, including the URL and credentials.&lt;/LI&gt;&lt;LI&gt;Verify the Splunk server running the add-on can connect to the MS server.&amp;nbsp; Use &lt;FONT face="courier new,courier"&gt;curl&lt;/FONT&gt; or a similar tool.&lt;/LI&gt;&lt;LI&gt;Check splunkd.log for related messages.&lt;/LI&gt;&lt;LI&gt;Check the MS logs for related messages.&lt;/LI&gt;&lt;LI&gt;If you're using Splunk search to see if data is coming in then double-check the SPL.&amp;nbsp; Verify the index name.&amp;nbsp; Try specifying &lt;FONT face="courier new,courier"&gt;latest=+1y&lt;/FONT&gt; to account for timestamp errors.&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Fri, 26 Jul 2024 00:21:47 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-07-26T00:21:47Z</dc:date>
    <item>
      <title>MS security integration with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694295#M115373</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Data is not getting indexed after adding the conf&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 14:36:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694295#M115373</guid>
      <dc:creator>pavithra</dc:creator>
      <dc:date>2024-07-25T14:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: MS security integration with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694301#M115374</link>
      <description>&lt;P&gt;Data will not be indexed automatically after adding the add-on.&amp;nbsp; Inputs must be configured so the add-on knows where to find the data.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Configure" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Configure&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 15:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694301#M115374</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-25T15:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: MS security integration with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694303#M115375</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi ,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;I have added the config details already&amp;nbsp; , still data is not coming&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 15:29:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694303#M115375</guid>
      <dc:creator>pavithra</dc:creator>
      <dc:date>2024-07-25T15:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: MS security integration with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694360#M115376</link>
      <description>&lt;P&gt;Typical GDI troubleshooting steps include:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Verify the input configuration, including the URL and credentials.&lt;/LI&gt;&lt;LI&gt;Verify the Splunk server running the add-on can connect to the MS server.&amp;nbsp; Use &lt;FONT face="courier new,courier"&gt;curl&lt;/FONT&gt; or a similar tool.&lt;/LI&gt;&lt;LI&gt;Check splunkd.log for related messages.&lt;/LI&gt;&lt;LI&gt;Check the MS logs for related messages.&lt;/LI&gt;&lt;LI&gt;If you're using Splunk search to see if data is coming in then double-check the SPL.&amp;nbsp; Verify the index name.&amp;nbsp; Try specifying &lt;FONT face="courier new,courier"&gt;latest=+1y&lt;/FONT&gt; to account for timestamp errors.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 26 Jul 2024 00:21:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-security-integration-with-splunk/m-p/694360#M115376</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-26T00:21:47Z</dc:date>
    </item>
  </channel>
</rss>

