All Apps and Add-ons

Windows Infrastructure App doesn't detects Users/Groups and Domain Controllers

cilea
New Member

Hi,

i've made a fresh setup of Splunk 6.1 and Windows infrasstructure app.
I followed row by row the setup guide of the app and the forwarders. I've a windows 2008 domain with two domain controllers but in the app configuration it doesn't detect any data about USers Login/logoff , groups and domain controllers.
However detects the Domain, DNS, and the events from domain controllers.
The ldap.conf file is structured as follow:

[default]

server=192.168.x.x (primary controller IP)

[intranet.mydomain.com]

server = PRIDC.intranet.mydomain.com

//# port = 636

//# ssl = true

basedn = DC=intranet,DC=mydomain,DC=com

binddn = CN=Splunk,CN=Users,DC=intranet,DC=mydomain,DC=com

password = xxxxxxxxxxxxx

alternatedomain = INTRANET

If we search using the standard search of Splunk we find all the events needed expecially the security events Login/Logoff with usernaem and Computers associated but the windows infr app seems that cannot retrieve these events to build the Users/Groups Views.
Also the SA-Ldap search does all the searches very well.

Universal forwarders have been configured following the instructions in the User Manual of Windows Infr App.
Here the list of modules on forwarders in Windows DCs:
Splunk_TA_windows
TA-DNSServer-NT6
TA-DomainController-NT6
SA-ModularInput-PowerShell(script execution tested and ok)
And the list of modules on Splunk Server:
Windows Infrastr App
SA-ldapsearch

How can i resolve these issues? What is a configuration that enables the build of lookup tables about Users and Groups?

Any help is appreciated.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

You need to install the Splunk_TA_windows on the Splunk instance as well.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...