All Apps and Add-ons

Why am I getting an error trying to configure the Splunk App for Windows Infrastructure without a search head?

tsekali
Explorer

Hi everyone.

I am trying to configure the Splunk App for Windows Infrastructure. My topology includes 2 Windows Domain Controllers, one Windows Exchange Server, one win File Server, and 2 cisco devices. Windows machines are running a universal forwarder each, an indexer runs splunk enterprise 6.2.1 on ubuntu 14 and there is no Search Head. The indexer is responsible for both indexing and searching.

About the app, the following is set up:
Splunk v6.2.1
Splunk Add-on for Microsoft Windows v4.7.3
Splunk Supporting Add-on for Microsoft Windows Active Directory v2.0.1

The user with winfra-admin user role and everything is marked with a green "tick". Besides that, continuing the wizard I get the following error:

Search "sourcetype="MSAD*" | head 5" did not return any events in the last 24 hours 

I read that Splunk Supporting Add-on for Microsoft Windows Active Directory should be installed on the search head (which is not present in my topology because I found there is no need to have one). Does anyone know what might be the problem?

Thank you!

jofe
Explorer

Hello,

Have you added the AD relevant TA:s to the domain controllers? MSAD data is generally grabbed through powershell scripts running on the domain controller. (You need powershell execution rights as well for this to work)

0 Karma

tsekali
Explorer

People....I am confused like big time here....!!

Is there any other add-on than Splunk Supporting Add-on for Active Directory ??

0 Karma

malmoore
Splunk Employee
Splunk Employee

No. There are no other add-ons than the ones you listed. As well, the Splunk Supporting Add-on for Active Directory is not applicable to the problems you experience.

Please read my response from 2 days ago as a starting point.

0 Karma

tsekali
Explorer

Also, in the documentation I see that The Splunk Supporting Add-on for Active Directory can be installed on a search head.
It does not perform any function when installed on a forwarder or indexer
. Am I doing something wrong?
My topology does not have a search head. Am I able to setup this app ??

0 Karma

malmoore
Splunk Employee
Splunk Employee

If you do not have a search head in your topology, then your indexer is the search head by default. So there is no issue there.

The data check for Active Directory is failing. This is because either:

  • The msad index does not exist on your indexer
  • The domain controllers are not sending data to the msad index - they only do this if you installed the correct Active Directory add-on in the universal forwarder on each DC.
  • The user has not been set up to search the msad index by default.

More info at the Splunk App for Windows Infrastructure Troubleshooting Page.

0 Karma

jofe
Explorer

Like malmoore says,

You need more than the configuration on the search head / indexer for this to work. Please review his answer and verify that you have an MSAD index, and that you have installed the correct addon on the DOMAIN CONTROLLERS.

0 Karma

tsekali
Explorer

Thanks for your answer!
Do you mean the Splunk Supporting Add-on for Microsoft Windows Active Directory v2.0.1 ? I have this one installed on the indexer and it is marked as OK.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...