All Apps and Add-ons

Is the Splunk App for Windows Infrastructure functional without a Domain Controller?

DotTest37
Path Finder

I need to index and search Event Logs from a few Windows 7 and 8 Desktops, but I don't use a Domain Controller.
This app has some prerequisites on the Configuration page, and it won't let me continue unless I specify AD parameters.

How can I use this app without a Domain Controller?

Dotty...

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

This a current known bug in the Windows Infra app. Should be fixed next release.

Current work around, install a domain controller with relevant AD TA's and index the data to get the data sources available.

Another option I proposed in a previous post: Install eventgen and the windows AD TA's and enable eventgen for a little bit. This should generate the required data sources, and hopefully allow the app to be installed. I havent heard back if this worked.

If you try the datagen, post the results, as that is the quickest and easiest fix.

0 Karma

DotTest37
Path Finder

Lets say I install the Domain Controller, do I need the Windows Desktops to join the Domain? because I cant do that.
Also, will a be able to remove the DC after I finished configuring the AD TA and keep indexing the Desktops?

0 Karma

malmoore
Splunk Employee
Splunk Employee

Yes, you should be able to remove the DC once you get the required events to pass the data check.

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...