All Apps and Add-ons

Splunk app for windows ad object monitoring

catchvjay
New Member

Hi,

We are trying to setup splunk app for Windows ad object monitoring as per MS Windows AD Objects | Splunkbase. Here we already have Windows TA Infrastructure app configured and sending logs to separate indexes rather than default mentioned in the app.

Whenever I provide that index name in macro and run autocheck, it is not able to detect the data in that index. When I search that index in splunk search, I can see data coming into that index.

We have data configured in xml based log format instead of classic ones. We have following setup.

catchvjay_0-1612883767419.png

What could be the reason this app is not able to detect the data?

 

Labels (1)
0 Karma

ajacobi
Path Finder

I'm experiencing this also. Will post if i find anything to explain why 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...