All Apps and Add-ons

How to get past "Check Data" screen in Splunk App for Windows Infrastructure without WinPrintMon data?

DaClyde
Contributor

I finally got past the Active Directory stage on the Prerequisites screen and am now stuck on the "Check Data" screen. How to I disable the WinPrintMon option? My data center has no printers and thus has no printer-related information to monitor. However, I can't get past this step in the set up because it can't find any WinPrintMon data.

It really seems like this App could benefit from several options up front for choosing which items are needed (LDAP/AD, Print monitoring, perfmon, etc.), instead of expecting users to populate everything by default.

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

Hi there. If you would, WinPrintMon should show as a Warning only, not an error. The key errors that are preventing you from moving on should be listed in addition to this WinPrintMon warning in the same section for the item that is not found.

0 Karma

DaClyde
Contributor

Warning or not, I still don't have a Next button to click. I'll add some dummy data as suggested and see if that does the trick. I'm also missing WMI data, but I'm not sure what that's supposed to be or where it should live. That is also just a warning. So I have two warnings, no errors, but Next is grayed out.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Can you also confirm that the Splunk Add-on for Windows and the Splunk Supporting Add-on for Active Directory have both been activated (not just installed)? Thanks.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Hi DaClyde,
unfortunately, the app does not have a built-in way to skip data verification steps.
However, the only thing the app does is run a couple of searches for the relevant sourcetypes with a | head 5 at the end.
So if you create a dummy data file with at least five events and index it into a test index with the expected sourcetypes such that the validation searches can find them, you will be able to get past that hurdle.

Not pretty, agreed, but currently the only workaround.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...