- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Data not displayed for App:Splunk App for Active Directory and 'Security Dashabord
No Data displayed for App:Splunk App for Active Directory and 'Security Dashabord' Views ‘Failed Logon over Time’, ‘Failed logon by Reason’ , ‘Failed logons by IP Address’ and ‘failed logon by User'
I have installed -Splunk_for_ActiveDirectory.
1) Domain Controller has Universal Forwarder (Version=6.0.2)
OS Version : OS Name Microsoft(R) Windows(R) Server 2003, Standard Edition (Version 5.2.3790 Service Pack 2 Build 3790)
Case:163029:Splunk 6 upgrade broke UF forwarding
Splunk Universal Version : 6.0.2
TA installed :
-Splunk_TA_windows (version = 4.6.4)
-SA-ldapsearch (version = 1.1.10 )
-TA-DNSServer-NT5 (version=1.2.2)
-TA-DomainController-NT5 (version=1.2.2)
2) The Indexer cum Search Head
OS Version : Linux
Splunk Version : 6.0.1
App and TA :
-Splunk_for_ActiveDirectory (version = 1.2.2)
-SA-ldapsearch (version = 1.1.11)
-Splunk_for_Exchange (version = 2.1.2)
-Splunk_TA_windows (version = 4.6.
*Issue ::::No Data is displayed for 'App:Splunk App for Active Directory ' and 'Security'Dashabord : User Long on Failure. See screenshot below
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


This behavior has been identified as bug -- MSAPP-1114:Inconsistent extraction between NT5 and NT6 for failed logins.
Expected to be fixed by Windows TA 4.7.
