<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic eDirectory events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101865#M21344</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;

&lt;P&gt;Has anyone successfully captured audit events from the Novell Audit agent for eDirectory or IDM products? I am new to SPLUNK and wonder if this is possible. I have had a look at your free edition, and have setup a TCP listener on the correct port (1289) which forwards onto an index specifically for this event source type. I have configured the audit events from the eDirectory side and generated some sample events, yet nothing appears in SPLUNK under that index. &lt;/P&gt;

&lt;P&gt;Is there some other steps to follow. Apologies in advance if I have missed something obvious as I am completely new to SPLUNK.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jan 2013 15:25:56 GMT</pubDate>
    <dc:creator>splunker2013</dc:creator>
    <dc:date>2013-01-28T15:25:56Z</dc:date>
    <item>
      <title>eDirectory events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101865#M21344</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;

&lt;P&gt;Has anyone successfully captured audit events from the Novell Audit agent for eDirectory or IDM products? I am new to SPLUNK and wonder if this is possible. I have had a look at your free edition, and have setup a TCP listener on the correct port (1289) which forwards onto an index specifically for this event source type. I have configured the audit events from the eDirectory side and generated some sample events, yet nothing appears in SPLUNK under that index. &lt;/P&gt;

&lt;P&gt;Is there some other steps to follow. Apologies in advance if I have missed something obvious as I am completely new to SPLUNK.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 15:25:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101865#M21344</guid>
      <dc:creator>splunker2013</dc:creator>
      <dc:date>2013-01-28T15:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: eDirectory events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101866#M21345</link>
      <description>&lt;P&gt;Anyone have any thoughts? Surely I am not the first to have tried this?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2013 09:56:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101866#M21345</guid>
      <dc:creator>splunker2013</dc:creator>
      <dc:date>2013-01-30T09:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: eDirectory events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101867#M21346</link>
      <description>&lt;P&gt;Saw this - hope its useful: &lt;A href="http://splunk-base.splunk.com/answers/8688/monitoring-novell-edirectory-events-with-splunk"&gt;http://splunk-base.splunk.com/answers/8688/monitoring-novell-edirectory-events-with-splunk&lt;/A&gt;&lt;BR /&gt;
br&lt;BR /&gt;
D&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2013 11:05:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101867#M21346</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2013-01-30T11:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: eDirectory events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101868#M21347</link>
      <description>&lt;P&gt;Thanks for the link Dave. I had come across that previously, however it doesn't seem to explain how this is setup. I have had a look at the associated link on the answer, but still no closer to understanding what I would need to change.&lt;/P&gt;

&lt;P&gt;I am using the latest patches of Novell Audit on a fairly new Audit VM, sending events on port 1289. I have a Splunk free box setup listening on 1289 but it never receives any audit events.It might be I have missed something in Splunk as I am new to this product.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 16:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101868#M21347</guid>
      <dc:creator>splunker2013</dc:creator>
      <dc:date>2013-02-06T16:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: eDirectory events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101869#M21348</link>
      <description>&lt;P&gt;Hi, hopefully you have solved your problem by now, but in case you didn't... Two very important questions first;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Are you sure that you are NOT getting the events? &lt;/LI&gt;
&lt;LI&gt;How did you check that?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;You say you created a new index to store these events - but does your role have access rights to the index in question. Also, if you have, does this index get searched by default? &lt;BR /&gt;
Go to Manager -&amp;gt; Access Controls -&amp;gt; Roles -&amp;gt; your role. At the bottom of the page you should find settings that control which indexes you can search.&lt;/P&gt;

&lt;P&gt;Have you monitored network traffic on the port in question? Firewall in between?&lt;/P&gt;

&lt;P&gt;Are the timestamps a possible source of trouble? If they are not parsed correctly, your events may end up in a different hour/day or even year. So running a search for 'last 60 min' may not be sufficient. Try a search for 'All time'. &lt;/P&gt;

&lt;P&gt;Sorry if this seems like basic stuff - but these are probably the most common reasons why users do not see the events they are expecting to.&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2013 11:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101869#M21348</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-03-25T11:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: eDirectory events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101870#M21349</link>
      <description>&lt;P&gt;Greetings;&lt;/P&gt;

&lt;P&gt;I have a similiar eDirectory setup, and I am seeing LDAP data in my logs.&lt;/P&gt;

&lt;P&gt;None of my ldap data is getting searched by my LDAP app, do I need to define a sourcetype?&lt;/P&gt;

&lt;P&gt;My data currently contains "source=tcp:1289", and "sourcetype=syslog".&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 20:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101870#M21349</guid>
      <dc:creator>genrehawk</dc:creator>
      <dc:date>2014-08-25T20:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: eDirectory events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101871#M21350</link>
      <description>&lt;P&gt;You could use xdas, just use a pattern with no timestamp and index it as json.&lt;BR /&gt;
I do a fair lot of edirectory and idm stuff if you need more...&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 09:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/eDirectory-events/m-p/101871#M21350</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2018-08-17T09:34:54Z</dc:date>
    </item>
  </channel>
</rss>

