All Apps and Add-ons

Splunk App for Active Directory and CSV Files

wagnerbianchi
Splunk Employee
Splunk Employee

Hi Folks,

After to review all the AD App for Splunk set up using Splunk Blogs (http://blogs.splunk.com/2012/10/21/splunk-app-for-active-directory-and-the-top-10-issues/) and AD online manual (http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/AbouttheSplunkAppforActiveDirec...), I am still facing problems related with the scheduled searches to feed CSV files used by AD App - I am still seeing an up message "No Matching Fields". After to fill up manually CSV files with some example data, that up message stop appearing and now the data I putted into the files is appearing as a Domain, Forest, Site and Servers.

Having that in mind I ask you: files are not being written by the AD's App, what is happening with the set up? Any clue, pls?

Thanks a lot, cheers!

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

This is a basic "no data is being collected" problem. Either (a) the audit information is not being collected or (b) the PowerShell scripts are not being run. Go back and check which data sources are not being collected and concentrate on those. Some are Security logs and some are PowerShell output.

Unfortunately, you have not provided any information about what CSV files, what data, what your tests have so far been. Thus, I can only provide generalized information.

0 Karma

wagnerbianchi
Splunk Employee
Splunk Employee

I really don't have a way to check it out this time, since this environment is running inside customer's facility. Is there a way to check whether the data is being extracted by scripts? Somewhere I can get the scripts execution time and check if they are collecting some results from them execution? Thanks a lot for the help Adrian.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...