<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DSBind Failed in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/DSBind-Failed/m-p/610754#M8975</link>
    <description>&lt;P&gt;ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::connectToDC: DsBind failed: (5)&lt;/P&gt;&lt;P&gt;We have 22 out of 3000+ hosts sending thousands of errors for this and I can't seem to figure out why. My best guess at this point is the forwarders need to be updated.&amp;nbsp; We have a distributed environment with multiple DC's.&amp;nbsp; Any idea if I'm doing something wrong on my end, or do I need to have these forwarders that are causing errors fixed?&lt;/P&gt;&lt;P&gt;I have things set up as follows:&lt;/P&gt;&lt;P&gt;All Windows hosts Universal Forwarders - inputs.conf -&lt;/P&gt;&lt;P&gt;[default]&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;Domain Controller UF inputs -&lt;/P&gt;&lt;P&gt;[admon://DefaultTargetDC]&lt;BR /&gt;targetDc = 'DC02'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;index = msad&lt;BR /&gt;monitorSubtree = 1&lt;BR /&gt;disabled = 0&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 1&lt;/P&gt;&lt;P&gt;[admon://SecondTargetDC]&lt;BR /&gt;targetDc = 'DC03'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;index = msad&lt;BR /&gt;monitorSubtree = 1&lt;BR /&gt;disabled = 1&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://ThirdTargetDC]&lt;BR /&gt;targetDc = 'DC01'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://FourthTargetDC]&lt;BR /&gt;targetDc = 'DC02'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://FifthTargetDC]&lt;BR /&gt;targetDc = 'DC01'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=adu&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://FifthTargetDC]&lt;BR /&gt;targetDc = 'DC01dev'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://SixthTargetDC]&lt;BR /&gt;targetDc = 'DC04'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://SeventhTargetDC]&lt;BR /&gt;targetDc = 'DC05'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://EighthTargetDC]&lt;BR /&gt;targetDc = 'DC06'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://NearestDC]&lt;BR /&gt;disabled = 1&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2022 20:18:27 GMT</pubDate>
    <dc:creator>walsborn</dc:creator>
    <dc:date>2022-08-24T20:18:27Z</dc:date>
    <item>
      <title>DSBind Failed</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/DSBind-Failed/m-p/610754#M8975</link>
      <description>&lt;P&gt;ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::connectToDC: DsBind failed: (5)&lt;/P&gt;&lt;P&gt;We have 22 out of 3000+ hosts sending thousands of errors for this and I can't seem to figure out why. My best guess at this point is the forwarders need to be updated.&amp;nbsp; We have a distributed environment with multiple DC's.&amp;nbsp; Any idea if I'm doing something wrong on my end, or do I need to have these forwarders that are causing errors fixed?&lt;/P&gt;&lt;P&gt;I have things set up as follows:&lt;/P&gt;&lt;P&gt;All Windows hosts Universal Forwarders - inputs.conf -&lt;/P&gt;&lt;P&gt;[default]&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;Domain Controller UF inputs -&lt;/P&gt;&lt;P&gt;[admon://DefaultTargetDC]&lt;BR /&gt;targetDc = 'DC02'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;index = msad&lt;BR /&gt;monitorSubtree = 1&lt;BR /&gt;disabled = 0&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 1&lt;/P&gt;&lt;P&gt;[admon://SecondTargetDC]&lt;BR /&gt;targetDc = 'DC03'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;index = msad&lt;BR /&gt;monitorSubtree = 1&lt;BR /&gt;disabled = 1&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://ThirdTargetDC]&lt;BR /&gt;targetDc = 'DC01'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://FourthTargetDC]&lt;BR /&gt;targetDc = 'DC02'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://FifthTargetDC]&lt;BR /&gt;targetDc = 'DC01'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=adu&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://FifthTargetDC]&lt;BR /&gt;targetDc = 'DC01dev'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://SixthTargetDC]&lt;BR /&gt;targetDc = 'DC04'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://SeventhTargetDC]&lt;BR /&gt;targetDc = 'DC05'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://EighthTargetDC]&lt;BR /&gt;targetDc = 'DC06'&lt;BR /&gt;startingNode = LDAP://OU=Computers,DC=ad&lt;BR /&gt;disabled = 1&lt;BR /&gt;index = msad&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;&lt;P&gt;[admon://NearestDC]&lt;BR /&gt;disabled = 1&lt;BR /&gt;baseline = 0&lt;BR /&gt;evt_resolve_ad_obj = 0&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 20:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/DSBind-Failed/m-p/610754#M8975</guid>
      <dc:creator>walsborn</dc:creator>
      <dc:date>2022-08-24T20:18:27Z</dc:date>
    </item>
  </channel>
</rss>

