Foi realizado a instalação do Splunk Infraestructure, com os pré-requisitos todos validados e realizado os deploy para os servidores de active Directory
Porém ao realizar a detecção dos recursos os controladores de Dominios não são encontrados. Não consegui achar um post no forum para resolver esta situação.
Hi unimedcba,
could you re edit your question in english?
Anyway, I'm latin (Italian) so your language isn't so different from mine!
If I correctly understood, you installed AD TAs but you don't see data.
Run this search: index=msad
if you have results, it means that data are arriving but your searches doesn't see them probably because they are out od the default search path.
In this case, you can add msad index to the default search path or modify the search that creates lookups inserting also the condition index=msad
.
If you don't see data, you have to troubleshoot your architecture.
Bye.
Giuseppe
As I said, you already are receiving data on you indexers, so the problem is in the scheduled searches to populate lookups because the msad index is out of default search path and in the macros and eventtype usually there isn't the filer on index (index=msad
).
You have to ways:
The first solution is easier:
in this way your lookups should be populated with your data.
Bye.
Giuseppe
P.S.: to answer to my comment, add a new comment to this answer, don't insert a new anwser.
Thanks for you
Hi unimedcba,
if you're satisfied of this answer, please accept and/or upvote it.
Bye, see next time.
Giuseppe