<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder DsBind failed since upgrade to 6.0.2 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172015#M34685</link>
    <description>&lt;P&gt;i still get the same error even after adding that &lt;/P&gt;</description>
    <pubDate>Sat, 09 Jan 2016 01:28:45 GMT</pubDate>
    <dc:creator>boopaljothi</dc:creator>
    <dc:date>2016-01-09T01:28:45Z</dc:date>
    <item>
      <title>Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172005#M34675</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;i juste upgraded my universal Forwarder on a windows server, &lt;/P&gt;

&lt;P&gt;and since it gives me this error in Splunkd.log&lt;/P&gt;

&lt;P&gt;ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::connectToDC: DsBind failed: (1722)&lt;/P&gt;

&lt;P&gt;forwarder is still working but serveclass didn't update ... &lt;/P&gt;

&lt;P&gt;help would be greate &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2014 16:17:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172005#M34675</guid>
      <dc:creator>Ed_Alias</dc:creator>
      <dc:date>2014-03-03T16:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172006#M34676</link>
      <description>&lt;P&gt;Same here. I ran across this while troubleshooting the fact that the wineventlogs stopped coming across on a couple of DCs. Whatever is causing this...not fun.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2014 20:21:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172006#M34676</guid>
      <dc:creator>itopsdci</dc:creator>
      <dc:date>2014-03-04T20:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172007#M34677</link>
      <description>&lt;P&gt;FYI, I resolved this in my own Splunk deployment. In &lt;CODE&gt;$SPLUNK_HOME/etc/apps/$WINDOWS_ADDON/local/inputs.conf&lt;/CODE&gt; I had quotes around our domain name for &lt;EM&gt;evt_dc_name&lt;/EM&gt;. I removed them, the problem went away, and our wineventlog:security events stopped being delayed. This behavior began after upgrading our deployment to 6.0.2.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:02:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172007#M34677</guid>
      <dc:creator>itopsdci</dc:creator>
      <dc:date>2020-09-28T16:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172008#M34678</link>
      <description>&lt;P&gt;And thanks to you my forwader is happy again ! : &lt;/P&gt;

&lt;P&gt;TcpOutputProc - Connected to idx=10.2xx.xxx.xxx:9997 using ACK&lt;/P&gt;

&lt;P&gt;Thank you !&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2014 08:36:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172008#M34678</guid>
      <dc:creator>Ed_Alias</dc:creator>
      <dc:date>2014-03-05T08:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172009#M34679</link>
      <description>&lt;P&gt;I have that field blank and I am still getting the errors.  We use multiple domains so I am not sure if putting in a domain name is feasible.  Any other ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 21:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172009#M34679</guid>
      <dc:creator>robert_miller</dc:creator>
      <dc:date>2014-07-21T21:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172010#M34680</link>
      <description>&lt;P&gt;Same problem even with version 6.2 is there any fix on this ?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 14:20:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172010#M34680</guid>
      <dc:creator>arber</dc:creator>
      <dc:date>2015-01-05T14:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172011#M34681</link>
      <description>&lt;P&gt;If you are seeing these errors with a basic event logging setup and you don't have your universal forwarders talking to AD to resolve AD objects in events, you might want to try this in your inputs.conf:&lt;/P&gt;

&lt;P&gt;evt_resolve_ad_obj = 0&lt;/P&gt;

&lt;P&gt;This tells the forwarder not to try to resolve AD objects. The default with this input type is to do so but if you don't set up the AD binding with evt_dc_name or evt_dns_name it does not work so you will see tons of these errors.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:27:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172011#M34681</guid>
      <dc:creator>chanfoli</dc:creator>
      <dc:date>2020-09-29T07:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172012#M34682</link>
      <description>&lt;P&gt;Adding&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;&lt;BR /&gt;
evt_resolve_ad_obj = 0&lt;/P&gt;

&lt;P&gt;to inputs.conf (on our Universal Forwarders) fixed the problem here when our Windows AD server changed.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:52:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172012#M34682</guid>
      <dc:creator>nk-1</dc:creator>
      <dc:date>2020-09-29T07:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172013#M34683</link>
      <description>&lt;P&gt;do we need to add this in limits.conf or inputs.conf?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 22:36:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172013#M34683</guid>
      <dc:creator>boopaljothi</dc:creator>
      <dc:date>2016-01-06T22:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172014#M34684</link>
      <description>&lt;P&gt;&lt;CODE&gt;SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf&lt;/CODE&gt; &lt;BR /&gt;
only, in my setup.&lt;BR /&gt;
My apologies for the previous typo. Will fix it.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 22:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172014#M34684</guid>
      <dc:creator>nk-1</dc:creator>
      <dc:date>2016-01-06T22:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172015#M34685</link>
      <description>&lt;P&gt;i still get the same error even after adding that &lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2016 01:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172015#M34685</guid>
      <dc:creator>boopaljothi</dc:creator>
      <dc:date>2016-01-09T01:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder DsBind failed since upgrade to 6.0.2</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172016#M34686</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/34857"&gt;@arber&lt;/a&gt; have you tried the &lt;/P&gt;

&lt;P&gt;[default] &lt;BR /&gt;
evt_resolve_ad_obj = 0&lt;/P&gt;

&lt;P&gt;fix?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:54:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-DsBind-failed-since-upgrade-to-6-0-2/m-p/172016#M34686</guid>
      <dc:creator>slebbie_splunk</dc:creator>
      <dc:date>2020-09-29T17:54:50Z</dc:date>
    </item>
  </channel>
</rss>

