All Apps and Add-ons

sourcetype="ActiveDirectory*"

ybahat
New Member

I just installed Splunk App for Windows Infrastructure v 1.1.2, and deployed the TA-DomainController-2012R2 on one DC

However, the prequisite test fails, as it finds no events when looking for sourcetype="ActiveDirectory*".

I searched the entire AddOn, and couldn't find any reference to that sourcetype anywhere.

Also, maybe its just metadata, but the App information for this add on is a copy of TA-DomainController-NT6, listing it as the TA for Windows Server 2008. Pherhaps there is a problem with this TA?

0 Karma
1 Solution

gyslainlatsa
Motivator
0 Karma

ybahat
New Member

thank you, the error was completly unrelated and was caused by a failure of the forwarder to report back to the indexer.

0 Karma

gyslainlatsa
Motivator

good, go and vote

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...