All Apps and Add-ons

Active Directory

omprakash9998
Path Finder

Hi,

I am running splunk 6.6.3 . can anyone help me to Active Directory information into Splunk App for windows infrastructure. I have installed the Splunk AD addon and every sourcetype is eneabled on it. I am unable to get Groups, Group Plocy information, Organizational units information and Active Directory Health information.
All i am able to get is User Information. I am not able to generate default domain lookup tables.

Thanks in advance.

0 Karma

p_gurav
Champion

Can you try this command and check outcome:
https://docs.splunk.com/Documentation/SA-LdapSearch/2.1.6/User/Theldapsearchcommand

Also there is troubleshooting doc available:
https://docs.splunk.com/Documentation/SA-LdapSearch/2.1.6/User/UseSA-ldapsearchtotroubleshootproblem...

Also check _internal logs for any kind of error.

omprakash9998
Path Finder

the ldap search command is resturning all the user related information. I am also looking to get "eventtype=msad-dc-health" and "DomainList.csv" as there are lots of dependencies on these to populate all the dashboards.

_internal logs doesnot not show errors related to AD or Ldap. Mostly Perfmon Errors.

Thank you.

0 Karma

ajhstn
Explorer

Did you get anywhere with populating the msad-dc-health event type? I also cannot run some searches as "msad-dc-health" event type doesnt return anything.

0 Karma

omprakash9998
Path Finder

Yes. I have resolved the issue, I am able to collect all the logs from AD. I have followed the following posts and was able to resolve it.

https://www.splunk.com/blog/2012/10/21/splunk-app-for-active-directory-and-the-top-10-issues.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...