All Apps and Add-ons

Sourcetype "ActiveDirectory

franciscof
Explorer

I`ve just installed the wiindows app for windows infrastructure and it addons and when I run the prequisite test, it fails, as it finds no events when looking for sourcetype="ActiveDirectory*".

I searched the entire AddOn, and couldn't find any reference to that sourcetype anywhere.

Could you help me out? What can this be? Perhaps en error with the TA?

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

>> I`ve just installed the wiindows app for windows infrastructure and it addons and when I run the prequisite test, it fails, as it finds no events when looking for sourcetype="ActiveDirectory*".


Do you have enough sample logs/production logs ingested in ur splunk? Do you get any other events/logs from the other remaining source/sourcetypes from the windows infra app?  

 

> Could you help me out? What can this be? Perhaps en error with the TA?

please let us know more info about ur splunk setup? clustered or non-clustered? how big? HF or no?.. etc thanks. 

Best Regards,

Sekar

PS - your karma points will be my 2 cents!

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...