All Apps and Add-ons

Windows Infr App - Active Directory Part



I have installed the Windows Infrastructure App to check the Active Directory Dashboards/Reports.
I installed all Active Directory requirements (Add-ons) on the AD and Splunk Level as mentioned in the online guides.
I configured the AD settings in one of the Add-ons, and the connection testing to AD were successful. The user configured on the Splunk UF Service level is also full privileged.

My issue is: I created a user on the Active Directory.
On Splunk Reports App, when I searched for the event I found it. But, on the Windows App, I couldn't find it in the User Create report.


0 Karma
Get Updates on the Splunk Community!

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...