All Apps and Add-ons

Why '[indexer] Eventtype 'wineventlog-ds' does not exist or is disabled' still showing on my SH even I already installed the Splunk Add-on for Microsoft Active Directory on the indexer?

crizelle
Explorer

Splunk Add-on for Microsoft Active Directory installed on the sh and indexer is an updated version. We get to see results on the dashboard, but we are bothered by that yellow warning icon. Is there anything we can get rid of the warning? Are we missing something? Thanks in advance

Tags (1)

sjohnson_splunk
Splunk Employee
Splunk Employee

The eventtype does not exist in any of the windows apps on Splunkbase.

If you collect the windows directory services event log you can create a global eventtype that points to the index and source or sourcetype for that data.

If you do NOT collect the directory services event log, you can create something like this in any app and share it globally:

[wineventlog-ds]
search = index=badindex sourcetype=bad

Presumably this will not return any data and will run quickly so it should not add much overhead to searches that reference it.
Once the search bundle gets deployed to the indexers the errors will go away.

0 Karma

thilles
Explorer

@crizelle Did you solve this? Struggeling with the same problem.

0 Karma

p_gurav
Champion
0 Karma

crizelle
Explorer

We already checked on this answer. Correct me if I'm wrong. The following apps and add-ons are installed:

Search head- Splunk App for Windows Infrastructure, Splunk Add-on for Microsoft Active Directory, Splunk Supporting Add-on for Active Directory
Indexer - Splunk Add-on for Microsoft Active Directory, Windows DNS

Did I missed any add-on? Thanks in advance

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @crizelle

You actually need to install that addon on the search head. The search head will send the knowledge objects to the indexer by itself

https://docs.splunk.com/Documentation/DCADAddon/1.0.0/DCADAddon/Installationsteps

Hope this is helpful. All the best.

0 Karma

crizelle
Explorer

Hi @chrisyoungerjds ,

Yes I also installed it on the search head. I installed the same add-on to the indexer because the warning is telling that the eventtype is not existing or disabled in the indexer. We also used a universal forwarder for data collection that's why I installed the add-on in the indexer as per the documentation as well. But then, warning is still showing..

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...