All Apps and Add-ons

Data not displayed for App:Splunk App for Active Directory and 'Security Dashabord

sat94541
Communicator

No Data displayed for App:Splunk App for Active Directory and 'Security Dashabord' Views ‘Failed Logon over Time’, ‘Failed logon by Reason’ , ‘Failed logons by IP Address’ and ‘failed logon by User'

I have installed -Splunk_for_ActiveDirectory.

1) Domain Controller has Universal Forwarder (Version=6.0.2)
OS Version : OS Name Microsoft(R) Windows(R) Server 2003, Standard Edition (Version 5.2.3790 Service Pack 2 Build 3790)
Case:163029:Splunk 6 upgrade broke UF forwarding
Splunk Universal Version : 6.0.2
TA installed :
-Splunk_TA_windows (version = 4.6.4)
-SA-ldapsearch (version = 1.1.10 )
-TA-DNSServer-NT5 (version=1.2.2)
-TA-DomainController-NT5 (version=1.2.2)

2) The Indexer cum Search Head
OS Version : Linux
Splunk Version : 6.0.1
App and TA :
-Splunk_for_ActiveDirectory (version = 1.2.2)
-SA-ldapsearch (version = 1.1.11)
-Splunk_for_Exchange (version = 2.1.2)
-Splunk_TA_windows (version = 4.6.

*Issue ::::No Data is displayed for 'App:Splunk App for Active Directory ' and 'Security'Dashabord : User Long on Failure. See screenshot below

0 Karma

rbal_splunk
Splunk Employee
Splunk Employee

This behavior has been identified as bug -- MSAPP-1114:Inconsistent extraction between NT5 and NT6 for failed logins.

Expected to be fixed by Windows TA 4.7.

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...