All Apps and Add-ons

Is the Splunk App for Windows Infrastructure functional without a Domain Controller?

DotTest37
Path Finder

I need to index and search Event Logs from a few Windows 7 and 8 Desktops, but I don't use a Domain Controller.
This app has some prerequisites on the Configuration page, and it won't let me continue unless I specify AD parameters.

How can I use this app without a Domain Controller?

Dotty...

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

This a current known bug in the Windows Infra app. Should be fixed next release.

Current work around, install a domain controller with relevant AD TA's and index the data to get the data sources available.

Another option I proposed in a previous post: Install eventgen and the windows AD TA's and enable eventgen for a little bit. This should generate the required data sources, and hopefully allow the app to be installed. I havent heard back if this worked.

If you try the datagen, post the results, as that is the quickest and easiest fix.

0 Karma

DotTest37
Path Finder

Lets say I install the Domain Controller, do I need the Windows Desktops to join the Domain? because I cant do that.
Also, will a be able to remove the DC after I finished configuring the AD TA and keep indexing the Desktops?

0 Karma

malmoore
Splunk Employee
Splunk Employee

Yes, you should be able to remove the DC once you get the required events to pass the data check.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...