Following a botched attempt to install the app for Win. Infrastructure, on my second time around, I cannot get past the Prerequisites step in the Setup. All my check marks are green, but the Next button is grayed out. Since I removed, and reinstalled the app, is there some setting somewhere that needs to be cleared to let me proceed?
The First Time Run wizard in Windows Infrastructure app 1.1.0/1.1.1 and Microsoft Exchange app 3.1.0/3.1.1 also internally checks if the SA-ldapsearch app is enabled. Could you please make sure to enable the app, restart Splunk and then try again?
If you should still face the issue again, then please raise a support case (if not already done) and provide:
The Windows Infrastructure and Microsoft Exchange app known issues section have been amended as well:
http://docs.splunk.com/Documentation/MSApp/1.1.1/MSInfra/Releasenotes#Current_known_issues
http://docs.splunk.com/Documentation/MSExchange/3.1.1/DeployMSX/Releasenotes#Current_known_issues
Hope this helps.
The First Time Run wizard in Windows Infrastructure app 1.1.0/1.1.1 and Microsoft Exchange app 3.1.0/3.1.1 also internally checks if the SA-ldapsearch app is enabled. Could you please make sure to enable the app, restart Splunk and then try again?
If you should still face the issue again, then please raise a support case (if not already done) and provide:
The Windows Infrastructure and Microsoft Exchange app known issues section have been amended as well:
http://docs.splunk.com/Documentation/MSApp/1.1.1/MSInfra/Releasenotes#Current_known_issues
http://docs.splunk.com/Documentation/MSExchange/3.1.1/DeployMSX/Releasenotes#Current_known_issues
Hope this helps.
That did it! SA-ldapsearch was disabled, probably sometime when the first run through of the Wizard was abandoned. Once I re-enabled it, I got a configure option on the Active Directory part of the checklist.
This is currently under investigation. There is already a bug open for that and Engineering is working on it. In case of relevant updates, I will report them here, thanks.
Not sure why that is happening, but you might want to try:
Can one of you post a screenshot of what you're seeing? We have had no reports of this phenomenon so it would be interesting to see exactly what you see. This is on the data check page, correct?
I work with DaClyde and have the same problem, but only on one box. Here is a screenshot.
Hi,
There's much more on that page than just that.
It's also checking for Windows Add-on, Splunk Supporting Add-on for Active Directory, and user role configuration.
Is that all you're seeing?
What browser are you running, and what version of that browser? What OS and version?
Server is Win 2008 R2. Once the setup got stuck, here, it shows the same in all browsers, but for the sake of full disclosure,Chrome 40.0.2214.93m and IE 11.0.9600.17501 (can't get Firefox to connect since we forced all our Splunk instances to only use TLS 1.2).
Splunk Add-on for Microsoft Windows v4.7.3 detected.
Splunk Supporting Add-on for Microsoft Windows Active Directory v2.0.1 detected
And there are five users, and the built-in admin account that have the winfra-admin role. We are logging in as the admin account until we can get this working and then figure out what roles to assign to actual user accounts.
Okay, thanks for the info.
I'm not sure what is causing this behavior, but before we can get resources to look at it we need to have a case filed through Support. Please do so.
In the meantime, do you have another box available that you can try this on? We can at least isolate it to the machine or not.
I'm submitting a ticket this morning.
Already tried all of that. Using both IE and Chrome, so no shared cache, and I'd removed the app when I re-started the whole install process from scratch, following the letter of the documentation. I'm wondering if the app it self has some sort of cache, or if there was a specific index I could clear that might properly reset the app back to a true fresh starting point.
I am having the same issue and the application version for windows infrastructure is 1.1.1
I can confirm this problem with version 1.1.1 of this App. The button is grayed out when all the check marks are green. This is with Splunk 6.2.1 on Linux.
I'm using Splunk 6.2.1on Windows, same version of the app, 1.1.1.
I'm having the same problem. Is there any fix? Management wants to include Windows events into Splunk.