All Apps and Add-ons

Sourcetype "ActiveDirectory

franciscof
Explorer

I`ve just installed the wiindows app for windows infrastructure and it addons and when I run the prequisite test, it fails, as it finds no events when looking for sourcetype="ActiveDirectory*".

I searched the entire AddOn, and couldn't find any reference to that sourcetype anywhere.

Could you help me out? What can this be? Perhaps en error with the TA?

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

>> I`ve just installed the wiindows app for windows infrastructure and it addons and when I run the prequisite test, it fails, as it finds no events when looking for sourcetype="ActiveDirectory*".


Do you have enough sample logs/production logs ingested in ur splunk? Do you get any other events/logs from the other remaining source/sourcetypes from the windows infra app?  

 

> Could you help me out? What can this be? Perhaps en error with the TA?

please let us know more info about ur splunk setup? clustered or non-clustered? how big? HF or no?.. etc thanks. 

Best Regards,

Sekar

PS - your karma points will be my 2 cents!

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...