All Apps and Add-ons

Active Directory

omprakash9998
Path Finder

Hi,

I am running splunk 6.6.3 . can anyone help me to Active Directory information into Splunk App for windows infrastructure. I have installed the Splunk AD addon and every sourcetype is eneabled on it. I am unable to get Groups, Group Plocy information, Organizational units information and Active Directory Health information.
All i am able to get is User Information. I am not able to generate default domain lookup tables.

Thanks in advance.

0 Karma

p_gurav
Champion

Can you try this command and check outcome:
https://docs.splunk.com/Documentation/SA-LdapSearch/2.1.6/User/Theldapsearchcommand

Also there is troubleshooting doc available:
https://docs.splunk.com/Documentation/SA-LdapSearch/2.1.6/User/UseSA-ldapsearchtotroubleshootproblem...

Also check _internal logs for any kind of error.

omprakash9998
Path Finder

the ldap search command is resturning all the user related information. I am also looking to get "eventtype=msad-dc-health" and "DomainList.csv" as there are lots of dependencies on these to populate all the dashboards.

_internal logs doesnot not show errors related to AD or Ldap. Mostly Perfmon Errors.

Thank you.

0 Karma

ajhstn
Explorer

Did you get anywhere with populating the msad-dc-health event type? I also cannot run some searches as "msad-dc-health" event type doesnt return anything.

0 Karma

omprakash9998
Path Finder

Yes. I have resolved the issue, I am able to collect all the logs from AD. I have followed the following posts and was able to resolve it.

https://www.splunk.com/blog/2012/10/21/splunk-app-for-active-directory-and-the-top-10-issues.html

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...