All Apps and Add-ons

Splunk App for Active Directory and CSV Files

wagnerbianchi
Splunk Employee
Splunk Employee

Hi Folks,

After to review all the AD App for Splunk set up using Splunk Blogs (http://blogs.splunk.com/2012/10/21/splunk-app-for-active-directory-and-the-top-10-issues/) and AD online manual (http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/AbouttheSplunkAppforActiveDirec...), I am still facing problems related with the scheduled searches to feed CSV files used by AD App - I am still seeing an up message "No Matching Fields". After to fill up manually CSV files with some example data, that up message stop appearing and now the data I putted into the files is appearing as a Domain, Forest, Site and Servers.

Having that in mind I ask you: files are not being written by the AD's App, what is happening with the set up? Any clue, pls?

Thanks a lot, cheers!

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

This is a basic "no data is being collected" problem. Either (a) the audit information is not being collected or (b) the PowerShell scripts are not being run. Go back and check which data sources are not being collected and concentrate on those. Some are Security logs and some are PowerShell output.

Unfortunately, you have not provided any information about what CSV files, what data, what your tests have so far been. Thus, I can only provide generalized information.

0 Karma

wagnerbianchi
Splunk Employee
Splunk Employee

I really don't have a way to check it out this time, since this environment is running inside customer's facility. Is there a way to check whether the data is being extracted by scripts? Somewhere I can get the scripts execution time and check if they are collecting some results from them execution? Thanks a lot for the help Adrian.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...