All Apps and Add-ons

Splunk app for active directory event types not working

systemsatpayzon
Path Finder

none of the event types in eventtypes.conf under \Splunk\etc\apps\Splunk_for_ActiveDirectory\default\ work in search. For example if i search for "eventtype=wineventlog-security" i get "Unable to find an eventtype wineventlog-security" but if i instead search for the underlying search string "index=main source=WinEventLog:Security" i get a lot of events. it looks like all eventtypes under "splunk_TA_windows" are searchable but non of the eventtypes under plunk_for_ActiveDirectory.

What could be wrong

0 Karma
1 Solution

systemsatpayzon
Path Finder

I solved it after a day of troubleshooting 🙂 the problem was that the eventtypes where only accessible inside the app in splunk web, but i used the standard searchapp for testing. after searching in the search app inside splunk app for active directory it works like a charm

View solution in original post

0 Karma

systemsatpayzon
Path Finder

I solved it after a day of troubleshooting 🙂 the problem was that the eventtypes where only accessible inside the app in splunk web, but i used the standard searchapp for testing. after searching in the search app inside splunk app for active directory it works like a charm

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Sounds like in the search app you would just need to explicitly specify the index for the AD data. (index=x eventtype=y)

The TAs for Splunk App for Active Directory log events into one of three indices:

  • perfmon = All performance data
  • winevents = All Windows Event Log data
  • msad = Everything else
0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

Hello. Have you restarted Splunk between removing/re-adding the Splunk for Active Directory app?

0 Karma

systemsatpayzon
Path Finder

using btool i can see that settings from eventtypes.conf in \Splunk_for_ActiveDirectory\default are being consumed by splunk, how come i cannot search for those eventtypes??

0 Karma

systemsatpayzon
Path Finder

previously i had the splunk app for windows installed, but i have deleted it today. could that cause any problems?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...