Getting Data In

Active Directory APP - no Failed Logon Data

davidbaier
New Member

Hi, i need some help with the Active Directory APP installation because i cannot get any Failed Logon Data within the APP.

i am using the Trial Version of Splunk
- we have 1 Unix Indexer
- we have 1 Windows 2008 R2 Domaincontroller (Universal Client).

I installed on the Indexer:
Active Directory APP
(deployeed to the Domaincontroller TA-DomainController-NT6)
(deployeed to the Domaincontroller TA-DNSServer-NT6)
SA-ldapsearch and configured it, it works fine
Splunk Ad-on for Windows
(deployeed it to the Domaincontroller)
Sideview

On the Domaincontroller i installed:
Universal Forwarder
deployeed the TA-Domaincontroller-NT6 and DNSServer-NT6 and the Add-on for Windows

Now my question, the documentation says that when installing the Universal Forwarder on the domaincontroler "Do not enable any of the inputs during the installation". So i left on the last installation page all unchecked (no eventlogs, no AD monitoring, all unchecked). Is this right ? Bedause when i do that i cannot get any Faled Logon Data within the Active Directory APP. The ldap stuff is working fine, so i can see the green light and domain names and servernames within the Active Directory APP. What i am doing wrong ? Is it right that i do not need any Eventlogs separately configured at the Universal Forwarder to have those Failed logon Data ?

Thanks and best regards

Dave

Tags (1)
0 Karma

davidbaier
New Member

So, i will answer myself after some more investigation.

It seems on the Univeral Forwarder the Security logs needs to be enabled, so a inputs.conf needs to be copied to the following path: C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkTAwindows\local

with the following setting: [WinEventLog://Security] disabled = 0

That should do the trick, at least it is working for me now.

Dave

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...