All Apps and Add-ons

Splunk app for windows infrastructure no Active Directory/Group policy info

pmovrich
Explorer

I have some of the domain controller info being pulled into the app like whats listed under
Active directory > domains
Active Directory > domain controllers.

But i don't see any of the active directory user, groups, computers or group policy info.

I tried configuring the app through tools and settings option and that didn't help.

When i do a ldap search:

|ldapsearch domain=SPL search="(objectClass=user)"

I get zero results.

any help?

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

Have you configured the SA-ldapsearch/local/ldap.conf yet and turned on Auditing?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...