All Apps and Add-ons

Data not displayed for App:Splunk App for Active Directory and 'Security Dashabord

sat94541
Communicator

No Data displayed for App:Splunk App for Active Directory and 'Security Dashabord' Views ‘Failed Logon over Time’, ‘Failed logon by Reason’ , ‘Failed logons by IP Address’ and ‘failed logon by User'

I have installed -Splunk_for_ActiveDirectory.

1) Domain Controller has Universal Forwarder (Version=6.0.2)
OS Version : OS Name Microsoft(R) Windows(R) Server 2003, Standard Edition (Version 5.2.3790 Service Pack 2 Build 3790)
Case:163029:Splunk 6 upgrade broke UF forwarding
Splunk Universal Version : 6.0.2
TA installed :
-Splunk_TA_windows (version = 4.6.4)
-SA-ldapsearch (version = 1.1.10 )
-TA-DNSServer-NT5 (version=1.2.2)
-TA-DomainController-NT5 (version=1.2.2)

2) The Indexer cum Search Head
OS Version : Linux
Splunk Version : 6.0.1
App and TA :
-Splunk_for_ActiveDirectory (version = 1.2.2)
-SA-ldapsearch (version = 1.1.11)
-Splunk_for_Exchange (version = 2.1.2)
-Splunk_TA_windows (version = 4.6.

*Issue ::::No Data is displayed for 'App:Splunk App for Active Directory ' and 'Security'Dashabord : User Long on Failure. See screenshot below

0 Karma

rbal_splunk
Splunk Employee
Splunk Employee

This behavior has been identified as bug -- MSAPP-1114:Inconsistent extraction between NT5 and NT6 for failed logins.

Expected to be fixed by Windows TA 4.7.

Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...