<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Directory APP - no Failed Logon Data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-APP-no-Failed-Logon-Data/m-p/176725#M35456</link>
    <description>&lt;P&gt;Hi, i need some help with the Active Directory APP installation because i cannot get any Failed Logon Data within the APP.&lt;/P&gt;

&lt;P&gt;i am using the Trial Version of Splunk&lt;BR /&gt;
 - we have 1 Unix Indexer&lt;BR /&gt;
 - we have 1 Windows 2008 R2 Domaincontroller (Universal Client).&lt;/P&gt;

&lt;P&gt;I installed on the Indexer: &lt;BR /&gt;
Active Directory APP&lt;BR /&gt;
(deployeed to the Domaincontroller TA-DomainController-NT6) &lt;BR /&gt;
(deployeed to the Domaincontroller TA-DNSServer-NT6)&lt;BR /&gt;
SA-ldapsearch and configured it, it works fine&lt;BR /&gt;
Splunk Ad-on for Windows&lt;BR /&gt;
(deployeed it to the Domaincontroller)&lt;BR /&gt;
Sideview &lt;/P&gt;

&lt;P&gt;On the Domaincontroller i installed:&lt;BR /&gt;
Universal Forwarder&lt;BR /&gt;
deployeed the TA-Domaincontroller-NT6 and DNSServer-NT6 and the Add-on for Windows&lt;/P&gt;

&lt;P&gt;Now my question, the documentation says that when installing the Universal Forwarder on the domaincontroler "Do not enable any of the inputs during the installation". So i left on the last installation page all unchecked (no eventlogs, no AD monitoring, all unchecked). Is this right ? Bedause when i do that i cannot get any Faled Logon Data within the Active Directory APP. The ldap stuff is working fine, so i can see the green light and domain names and servernames within the Active Directory APP. What i am doing wrong ? Is it right that i do not need any Eventlogs separately configured at the Universal Forwarder to have those Failed logon Data ? &lt;/P&gt;

&lt;P&gt;Thanks and best regards&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2013 17:28:51 GMT</pubDate>
    <dc:creator>davidbaier</dc:creator>
    <dc:date>2013-12-12T17:28:51Z</dc:date>
    <item>
      <title>Active Directory APP - no Failed Logon Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-APP-no-Failed-Logon-Data/m-p/176725#M35456</link>
      <description>&lt;P&gt;Hi, i need some help with the Active Directory APP installation because i cannot get any Failed Logon Data within the APP.&lt;/P&gt;

&lt;P&gt;i am using the Trial Version of Splunk&lt;BR /&gt;
 - we have 1 Unix Indexer&lt;BR /&gt;
 - we have 1 Windows 2008 R2 Domaincontroller (Universal Client).&lt;/P&gt;

&lt;P&gt;I installed on the Indexer: &lt;BR /&gt;
Active Directory APP&lt;BR /&gt;
(deployeed to the Domaincontroller TA-DomainController-NT6) &lt;BR /&gt;
(deployeed to the Domaincontroller TA-DNSServer-NT6)&lt;BR /&gt;
SA-ldapsearch and configured it, it works fine&lt;BR /&gt;
Splunk Ad-on for Windows&lt;BR /&gt;
(deployeed it to the Domaincontroller)&lt;BR /&gt;
Sideview &lt;/P&gt;

&lt;P&gt;On the Domaincontroller i installed:&lt;BR /&gt;
Universal Forwarder&lt;BR /&gt;
deployeed the TA-Domaincontroller-NT6 and DNSServer-NT6 and the Add-on for Windows&lt;/P&gt;

&lt;P&gt;Now my question, the documentation says that when installing the Universal Forwarder on the domaincontroler "Do not enable any of the inputs during the installation". So i left on the last installation page all unchecked (no eventlogs, no AD monitoring, all unchecked). Is this right ? Bedause when i do that i cannot get any Faled Logon Data within the Active Directory APP. The ldap stuff is working fine, so i can see the green light and domain names and servernames within the Active Directory APP. What i am doing wrong ? Is it right that i do not need any Eventlogs separately configured at the Universal Forwarder to have those Failed logon Data ? &lt;/P&gt;

&lt;P&gt;Thanks and best regards&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 17:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-APP-no-Failed-Logon-Data/m-p/176725#M35456</guid>
      <dc:creator>davidbaier</dc:creator>
      <dc:date>2013-12-12T17:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory APP - no Failed Logon Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-APP-no-Failed-Logon-Data/m-p/176726#M35457</link>
      <description>&lt;P&gt;So, i will answer myself after some more investigation.&lt;/P&gt;

&lt;P&gt;It seems on the Univeral Forwarder the Security logs needs to be enabled, so a inputs.conf needs to be copied to the following path:
C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk&lt;EM&gt;TA&lt;/EM&gt;windows\local&lt;/P&gt;

&lt;P&gt;with the following setting:
[WinEventLog://Security]
disabled = 0&lt;/P&gt;

&lt;P&gt;That should do the trick, at least it is working for me now.&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2013 14:00:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Active-Directory-APP-no-Failed-Logon-Data/m-p/176726#M35457</guid>
      <dc:creator>davidbaier</dc:creator>
      <dc:date>2013-12-18T14:00:24Z</dc:date>
    </item>
  </channel>
</rss>

