All Apps and Add-ons

Sourcetype "ActiveDirectory

franciscof
Explorer

I`ve just installed the wiindows app for windows infrastructure and it addons and when I run the prequisite test, it fails, as it finds no events when looking for sourcetype="ActiveDirectory*".

I searched the entire AddOn, and couldn't find any reference to that sourcetype anywhere.

Could you help me out? What can this be? Perhaps en error with the TA?

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

>> I`ve just installed the wiindows app for windows infrastructure and it addons and when I run the prequisite test, it fails, as it finds no events when looking for sourcetype="ActiveDirectory*".


Do you have enough sample logs/production logs ingested in ur splunk? Do you get any other events/logs from the other remaining source/sourcetypes from the windows infra app?  

 

> Could you help me out? What can this be? Perhaps en error with the TA?

please let us know more info about ur splunk setup? clustered or non-clustered? how big? HF or no?.. etc thanks. 

Best Regards,

Sekar

PS - your karma points will be my 2 cents!

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...