All Apps and Add-ons

Splunk App for Windows Infrastructure: Why is the pre-built Active Directory new group search not working?

msaz
Path Finder

I've got everything installed and configured for the Splunk App for Windows Infrastructure. Most of the pre-built searches work fine, but the Active Directory -> Groups -> Security Group Reports -> Security Groups: New isn't returning any results even though I've made new groups recently and am running the search for the past 7 days.

Security Groups: All, Nested, etc. all seem to work fine.

0 Karma
1 Solution

msaz
Path Finder

Doh! UF wasn't installed on all DCs. Confirmed events are coming from DCs with the UF installed.

View solution in original post

0 Karma

msaz
Path Finder

Doh! UF wasn't installed on all DCs. Confirmed events are coming from DCs with the UF installed.

0 Karma

woodcock
Esteemed Legend

Did you deploy this app to the Active Directory servers and turn on the msad inputs by setting disabled=false inside of inputs.conf? Did you restart the splunk instances on those forwarders after deploying inputs.conf?

0 Karma

msaz
Path Finder

Yes, everything else seems to be working. I get results from other searches... Active Directory -> Groups -> Security Group Reports -> Security Groups: Empty returns results, as does All. The 'New' search is the only one that doesn't seem to be working.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...