I recently installed and configured Splunk Enterprise 7.0.2 on a Windows Server 2012 R2 server.
In addition to this, I installed and configured the:
Splunk Add-on for Microsoft Active Directory (1.0.0)
Splunk Supporting Add-on for Active Directory (2.1.6)
Splunk App for Windows Infrastructure (1.4.3)
Within Search & Reporting, I can see lots of incoming data from the Hosts (DC and Splunk server/indexer), Source (ActiveDirectory) and Sourcetype (ActiveDirectory).
However, when I launch the dashboards from any of the apps/add-ons (e.g. Active Directory Overview > Topology Report), there are no results found.
Within this dashboard, when I try to amend the Forest, Site, Domain or Server, nothing seems to work.
Can someone help with this, please?
Can anybody offer an opinion please?