I downloaded and configured Splunk App for Windows Infrastructure including the needed LDAP and powershell app (did not setup the PS app, that is only needed for 2012r2 and above) and configured the nessesary pieces but still having difficulty. The dashboards from the app are blank but if I open the same dashboard from the list of dashboards it works. It looks like there are two versions of each dashboard in the app, one works, one does not.
Example:
I can pull this dashboard from "View Dashboards" and it works nicely:
%SPLUNK_WEB%/dj/en-us/splunk_app_windows_infrastructure/palette/ActiveDirectory.UserUtilization677/
This dashboard is loaded from the link in nav/default.xml and does not work:
%SPLUNK_WEB%/dj/en-us/splunk_app_windows_infrastructure/ad/sec_user_utilization/
No error, just blank dashboard.
Also, when I run the detect script from the config page, I get "No active directory found" So I am guessing that may be related. I followed all the setup steps. I suspect there was a another step that may have been implicit that I missed.
The only next step I can think of is dig into the app files themselves.
Any other troubleshooting suggestions is much appreciated.
Thanks!
I was directed to the following post on Splunk Answers, which acknowledges that this is a bug in v1.0.1.
http://answers.splunk.com/answers/135849/app-for-windows-infrastructure-101
I also just received confirmation that v1.0.1.1, which contains a fix for this, is being released in a few hours.
For what it's worth, I didn't have the problem where it auto-detect my AD, but it did initially fail to detect users, groups and computers. Found out the problem was that the eventtypes ultimately were searching on index=main. I have nothing dumping to 'main'. A quick edit to customize those eventtypes to point to the correct index allowed them to be found through the auto-detect wizard.
OK, I just installed v1.0.2 and the issue appears to be fixed. I do have some other questionable things to look into (such as why it doesn't auto-detect AD Users and Groups and build menus/dashboards for those), but there's probably a reasonable explanation for that.
I was directed to the following post on Splunk Answers, which acknowledges that this is a bug in v1.0.1.
http://answers.splunk.com/answers/135849/app-for-windows-infrastructure-101
I also just received confirmation that v1.0.1.1, which contains a fix for this, is being released in a few hours.
This also worked for me!
Having the same problem. Anyone found an answer to this yet? I have a ticket opened with support; I'll update here if I hear anything useful.
Awesome! I hope we get an answer!