All Apps and Add-ons

Splunk App for Active Directory and CSV Files

wagnerbianchi
Splunk Employee
Splunk Employee

Hi Folks,

After to review all the AD App for Splunk set up using Splunk Blogs (http://blogs.splunk.com/2012/10/21/splunk-app-for-active-directory-and-the-top-10-issues/) and AD online manual (http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/AbouttheSplunkAppforActiveDirec...), I am still facing problems related with the scheduled searches to feed CSV files used by AD App - I am still seeing an up message "No Matching Fields". After to fill up manually CSV files with some example data, that up message stop appearing and now the data I putted into the files is appearing as a Domain, Forest, Site and Servers.

Having that in mind I ask you: files are not being written by the AD's App, what is happening with the set up? Any clue, pls?

Thanks a lot, cheers!

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

This is a basic "no data is being collected" problem. Either (a) the audit information is not being collected or (b) the PowerShell scripts are not being run. Go back and check which data sources are not being collected and concentrate on those. Some are Security logs and some are PowerShell output.

Unfortunately, you have not provided any information about what CSV files, what data, what your tests have so far been. Thus, I can only provide generalized information.

0 Karma

wagnerbianchi
Splunk Employee
Splunk Employee

I really don't have a way to check it out this time, since this environment is running inside customer's facility. Is there a way to check whether the data is being extracted by scripts? Somewhere I can get the scripts execution time and check if they are collecting some results from them execution? Thanks a lot for the help Adrian.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...