All Apps and Add-ons

sourcetype="ActiveDirectory*"

ybahat
New Member

I just installed Splunk App for Windows Infrastructure v 1.1.2, and deployed the TA-DomainController-2012R2 on one DC

However, the prequisite test fails, as it finds no events when looking for sourcetype="ActiveDirectory*".

I searched the entire AddOn, and couldn't find any reference to that sourcetype anywhere.

Also, maybe its just metadata, but the App information for this add on is a copy of TA-DomainController-NT6, listing it as the TA for Windows Server 2008. Pherhaps there is a problem with this TA?

0 Karma
1 Solution

gyslainlatsa
Motivator
0 Karma

ybahat
New Member

thank you, the error was completly unrelated and was caused by a failure of the forwarder to report back to the indexer.

0 Karma

gyslainlatsa
Motivator

good, go and vote

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...