Hi Folks,
After to review all the AD App for Splunk set up using Splunk Blogs (http://blogs.splunk.com/2012/10/21/splunk-app-for-active-directory-and-the-top-10-issues/) and AD online manual (http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/AbouttheSplunkAppforActiveDirec...), I am still facing problems related with the scheduled searches to feed CSV files used by AD App - I am still seeing an up message "No Matching Fields". After to fill up manually CSV files with some example data, that up message stop appearing and now the data I putted into the files is appearing as a Domain, Forest, Site and Servers.
Having that in mind I ask you: files are not being written by the AD's App, what is happening with the set up? Any clue, pls?
Thanks a lot, cheers!
This is a basic "no data is being collected" problem. Either (a) the audit information is not being collected or (b) the PowerShell scripts are not being run. Go back and check which data sources are not being collected and concentrate on those. Some are Security logs and some are PowerShell output.
Unfortunately, you have not provided any information about what CSV files, what data, what your tests have so far been. Thus, I can only provide generalized information.
I really don't have a way to check it out this time, since this environment is running inside customer's facility. Is there a way to check whether the data is being extracted by scripts? Somewhere I can get the scripts execution time and check if they are collecting some results from them execution? Thanks a lot for the help Adrian.