<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory inputs missing SYNC event types after 6.2.1 upgrade? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-inputs-missing-SYNC-event-types-after-6-2-1/m-p/112031#M23477</link>
    <description>&lt;P&gt;The solution is to remove the following line from the admon stanza in inputs.conf file in the system\default folder:&lt;/P&gt;

&lt;P&gt;baseline=0&lt;/P&gt;

&lt;P&gt;Adding baseline=1 to the inputs.conf in the system\local folder has no effect from what I could see.  This issue effects all versions of 6.2 and 6.3.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2016 19:57:16 GMT</pubDate>
    <dc:creator>corey_dick</dc:creator>
    <dc:date>2016-01-22T19:57:16Z</dc:date>
    <item>
      <title>Active Directory inputs missing SYNC event types after 6.2.1 upgrade?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-inputs-missing-SYNC-event-types-after-6-2-1/m-p/112029#M23475</link>
      <description>&lt;P&gt;As the question above states;&lt;/P&gt;

&lt;P&gt;Since the 6.2.1 update of Splunk, our active directory inputs are no longer gathering 'admonEventType=Sync' events.&lt;/P&gt;

&lt;P&gt;Sync events are the main meat of the AD indexes, containing the actual listing for objects.&lt;/P&gt;

&lt;P&gt;Our last _time entry is 12/16/2014 around 10am, immediately after the 6.2.1 update.&lt;/P&gt;

&lt;P&gt;The other 3 admonEventTypes are still collected.  Start, Scheme, update.&lt;/P&gt;

&lt;P&gt;I have recreated the inputs on 2 servers in different location, and the same behavior remains.  Only 3 of the event types are being collected.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2015 20:29:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-inputs-missing-SYNC-event-types-after-6-2-1/m-p/112029#M23475</guid>
      <dc:creator>mcrawford44</dc:creator>
      <dc:date>2015-07-09T20:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory inputs missing SYNC event types after 6.2.1 upgrade?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-inputs-missing-SYNC-event-types-after-6-2-1/m-p/112030#M23476</link>
      <description>&lt;P&gt;Splunk support was able to replicate this bug and have submitted a ticket; SPL-104212&lt;/P&gt;

&lt;P&gt;Awaiting response, and I will post any remediation steps here.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 19:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-inputs-missing-SYNC-event-types-after-6-2-1/m-p/112030#M23476</guid>
      <dc:creator>mcrawford44</dc:creator>
      <dc:date>2015-07-17T19:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory inputs missing SYNC event types after 6.2.1 upgrade?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-inputs-missing-SYNC-event-types-after-6-2-1/m-p/112031#M23477</link>
      <description>&lt;P&gt;The solution is to remove the following line from the admon stanza in inputs.conf file in the system\default folder:&lt;/P&gt;

&lt;P&gt;baseline=0&lt;/P&gt;

&lt;P&gt;Adding baseline=1 to the inputs.conf in the system\local folder has no effect from what I could see.  This issue effects all versions of 6.2 and 6.3.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 19:57:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-inputs-missing-SYNC-event-types-after-6-2-1/m-p/112031#M23477</guid>
      <dc:creator>corey_dick</dc:creator>
      <dc:date>2016-01-22T19:57:16Z</dc:date>
    </item>
  </channel>
</rss>

