All Apps and Add-ons

Sourcetype "ActiveDirectory

franciscof
Explorer

I`ve just installed the wiindows app for windows infrastructure and it addons and when I run the prequisite test, it fails, as it finds no events when looking for sourcetype="ActiveDirectory*".

I searched the entire AddOn, and couldn't find any reference to that sourcetype anywhere.

Could you help me out? What can this be? Perhaps en error with the TA?

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

>> I`ve just installed the wiindows app for windows infrastructure and it addons and when I run the prequisite test, it fails, as it finds no events when looking for sourcetype="ActiveDirectory*".


Do you have enough sample logs/production logs ingested in ur splunk? Do you get any other events/logs from the other remaining source/sourcetypes from the windows infra app?  

 

> Could you help me out? What can this be? Perhaps en error with the TA?

please let us know more info about ur splunk setup? clustered or non-clustered? how big? HF or no?.. etc thanks. 

Best Regards,

Sekar

PS - your karma points will be my 2 cents!

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...