All Apps and Add-ons

Windows Infr App - Active Directory Part

hnakhle
Explorer

Hello,

I have installed the Windows Infrastructure App to check the Active Directory Dashboards/Reports.
I installed all Active Directory requirements (Add-ons) on the AD and Splunk Level as mentioned in the online guides.
I configured the AD settings in one of the Add-ons, and the connection testing to AD were successful. The user configured on the Splunk UF Service level is also full privileged.

My issue is: I created a user on the Active Directory.
On Splunk Reports App, when I searched for the event I found it. But, on the Windows App, I couldn't find it in the User Create report.

Help!!

0 Karma
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...