All Apps and Add-ons

MS Windows AD Objects: "Warning - No ActiveDirectory baseline (Sync) Object data found."

richardphung
Communicator

I have followed the steps outlined here:
https://answers.splunk.com/answers/457116/ms-windows-ad-objects-how-to-troubleshoot-warning.html

With no luck.

Under Build AD Lookup Lists - Main >
Verify admon Object data:
WARNING!! - No ActiveDirectory baseline (Sync) Object data found. Verify the Deployment Steps outlined in the MS-Windows-AD-Objects Overview dashboard, specifically Deployment Steps 2 and 3.

under:
AD Objects - Verify Baseline Data - Overall

I get:
ObjectType Total Unique Objects Last Received Event Time Verify Collection and Completion
Domains 1 05/29/19 04:13:38 Baseline Collection Completed (22114 Minutes Ago)

0 Karma

richardphung
Communicator

Apparently, all I needed was a little more time.
About 20 minutes later, I get:

Verify admon
Object data:
SUCCESS - Found ActiveDirectory(admon) baseline (Sync) Object Data
View:
admon Verify Search

ObjectType Total Unique Objects Last Received Event Time Verify Collection and Completion
User 14332 06/13/19 12:52:51 Baseline Collection Completed (17 Minutes Ago)
Computer 2389 06/13/19 12:52:51 Baseline Collection Completed (17 Minutes Ago)
Group 1079 06/13/19 12:51:50 Baseline Collection Completed (18 Minutes Ago)
Organization Units 123 06/13/19 12:45:19 Baseline Collection Completed (25 Minutes Ago)
Group Policies 92 06/13/19 12:45:19 Baseline Collection Completed (25 Minutes Ago)
Containers 23 06/13/19 12:44:15 Baseline Collection Completed (26 Minutes Ago)
Domains 1 06/13/19 12:52:06 Baseline Collection Completed (18 Minutes Ago)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...