All Apps and Add-ons

Splunk App for Active Directory and CSV Files

wagnerbianchi
Splunk Employee
Splunk Employee

Hi Folks,

After to review all the AD App for Splunk set up using Splunk Blogs (http://blogs.splunk.com/2012/10/21/splunk-app-for-active-directory-and-the-top-10-issues/) and AD online manual (http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/AbouttheSplunkAppforActiveDirec...), I am still facing problems related with the scheduled searches to feed CSV files used by AD App - I am still seeing an up message "No Matching Fields". After to fill up manually CSV files with some example data, that up message stop appearing and now the data I putted into the files is appearing as a Domain, Forest, Site and Servers.

Having that in mind I ask you: files are not being written by the AD's App, what is happening with the set up? Any clue, pls?

Thanks a lot, cheers!

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

This is a basic "no data is being collected" problem. Either (a) the audit information is not being collected or (b) the PowerShell scripts are not being run. Go back and check which data sources are not being collected and concentrate on those. Some are Security logs and some are PowerShell output.

Unfortunately, you have not provided any information about what CSV files, what data, what your tests have so far been. Thus, I can only provide generalized information.

0 Karma

wagnerbianchi
Splunk Employee
Splunk Employee

I really don't have a way to check it out this time, since this environment is running inside customer's facility. Is there a way to check whether the data is being extracted by scripts? Somewhere I can get the scripts execution time and check if they are collecting some results from them execution? Thanks a lot for the help Adrian.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...