All Apps and Add-ons

Splunk app for windows ad object monitoring

catchvjay
New Member

Hi,

We are trying to setup splunk app for Windows ad object monitoring as per MS Windows AD Objects | Splunkbase. Here we already have Windows TA Infrastructure app configured and sending logs to separate indexes rather than default mentioned in the app.

Whenever I provide that index name in macro and run autocheck, it is not able to detect the data in that index. When I search that index in splunk search, I can see data coming into that index.

We have data configured in xml based log format instead of classic ones. We have following setup.

catchvjay_0-1612883767419.png

What could be the reason this app is not able to detect the data?

 

Labels (1)
0 Karma

ajacobi
Path Finder

I'm experiencing this also. Will post if i find anything to explain why 

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...