All Apps and Add-ons

Splunk app for active directory event types not working

systemsatpayzon
Path Finder

none of the event types in eventtypes.conf under \Splunk\etc\apps\Splunk_for_ActiveDirectory\default\ work in search. For example if i search for "eventtype=wineventlog-security" i get "Unable to find an eventtype wineventlog-security" but if i instead search for the underlying search string "index=main source=WinEventLog:Security" i get a lot of events. it looks like all eventtypes under "splunk_TA_windows" are searchable but non of the eventtypes under plunk_for_ActiveDirectory.

What could be wrong

0 Karma
1 Solution

systemsatpayzon
Path Finder

I solved it after a day of troubleshooting 🙂 the problem was that the eventtypes where only accessible inside the app in splunk web, but i used the standard searchapp for testing. after searching in the search app inside splunk app for active directory it works like a charm

View solution in original post

0 Karma

systemsatpayzon
Path Finder

I solved it after a day of troubleshooting 🙂 the problem was that the eventtypes where only accessible inside the app in splunk web, but i used the standard searchapp for testing. after searching in the search app inside splunk app for active directory it works like a charm

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Sounds like in the search app you would just need to explicitly specify the index for the AD data. (index=x eventtype=y)

The TAs for Splunk App for Active Directory log events into one of three indices:

  • perfmon = All performance data
  • winevents = All Windows Event Log data
  • msad = Everything else
0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

Hello. Have you restarted Splunk between removing/re-adding the Splunk for Active Directory app?

0 Karma

systemsatpayzon
Path Finder

using btool i can see that settings from eventtypes.conf in \Splunk_for_ActiveDirectory\default are being consumed by splunk, how come i cannot search for those eventtypes??

0 Karma

systemsatpayzon
Path Finder

previously i had the splunk app for windows installed, but i have deleted it today. could that cause any problems?

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...