All Apps and Add-ons

MS Windows AD Objects: "Warning - No ActiveDirectory baseline (Sync) Object data found."

richardphung
Communicator

I have followed the steps outlined here:
https://answers.splunk.com/answers/457116/ms-windows-ad-objects-how-to-troubleshoot-warning.html

With no luck.

Under Build AD Lookup Lists - Main >
Verify admon Object data:
WARNING!! - No ActiveDirectory baseline (Sync) Object data found. Verify the Deployment Steps outlined in the MS-Windows-AD-Objects Overview dashboard, specifically Deployment Steps 2 and 3.

under:
AD Objects - Verify Baseline Data - Overall

I get:
ObjectType Total Unique Objects Last Received Event Time Verify Collection and Completion
Domains 1 05/29/19 04:13:38 Baseline Collection Completed (22114 Minutes Ago)

0 Karma

richardphung
Communicator

Apparently, all I needed was a little more time.
About 20 minutes later, I get:

Verify admon
Object data:
SUCCESS - Found ActiveDirectory(admon) baseline (Sync) Object Data
View:
admon Verify Search

ObjectType Total Unique Objects Last Received Event Time Verify Collection and Completion
User 14332 06/13/19 12:52:51 Baseline Collection Completed (17 Minutes Ago)
Computer 2389 06/13/19 12:52:51 Baseline Collection Completed (17 Minutes Ago)
Group 1079 06/13/19 12:51:50 Baseline Collection Completed (18 Minutes Ago)
Organization Units 123 06/13/19 12:45:19 Baseline Collection Completed (25 Minutes Ago)
Group Policies 92 06/13/19 12:45:19 Baseline Collection Completed (25 Minutes Ago)
Containers 23 06/13/19 12:44:15 Baseline Collection Completed (26 Minutes Ago)
Domains 1 06/13/19 12:52:06 Baseline Collection Completed (18 Minutes Ago)

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...