All Apps and Add-ons

Splunk App for Windows Infrastructure: Why is the pre-built Active Directory new group search not working?

msaz
Path Finder

I've got everything installed and configured for the Splunk App for Windows Infrastructure. Most of the pre-built searches work fine, but the Active Directory -> Groups -> Security Group Reports -> Security Groups: New isn't returning any results even though I've made new groups recently and am running the search for the past 7 days.

Security Groups: All, Nested, etc. all seem to work fine.

0 Karma
1 Solution

msaz
Path Finder

Doh! UF wasn't installed on all DCs. Confirmed events are coming from DCs with the UF installed.

View solution in original post

0 Karma

msaz
Path Finder

Doh! UF wasn't installed on all DCs. Confirmed events are coming from DCs with the UF installed.

0 Karma

woodcock
Esteemed Legend

Did you deploy this app to the Active Directory servers and turn on the msad inputs by setting disabled=false inside of inputs.conf? Did you restart the splunk instances on those forwarders after deploying inputs.conf?

0 Karma

msaz
Path Finder

Yes, everything else seems to be working. I get results from other searches... Active Directory -> Groups -> Security Group Reports -> Security Groups: Empty returns results, as does All. The 'New' search is the only one that doesn't seem to be working.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...