Getting Data In

Active Directory APP - no Failed Logon Data

davidbaier
New Member

Hi, i need some help with the Active Directory APP installation because i cannot get any Failed Logon Data within the APP.

i am using the Trial Version of Splunk
- we have 1 Unix Indexer
- we have 1 Windows 2008 R2 Domaincontroller (Universal Client).

I installed on the Indexer:
Active Directory APP
(deployeed to the Domaincontroller TA-DomainController-NT6)
(deployeed to the Domaincontroller TA-DNSServer-NT6)
SA-ldapsearch and configured it, it works fine
Splunk Ad-on for Windows
(deployeed it to the Domaincontroller)
Sideview

On the Domaincontroller i installed:
Universal Forwarder
deployeed the TA-Domaincontroller-NT6 and DNSServer-NT6 and the Add-on for Windows

Now my question, the documentation says that when installing the Universal Forwarder on the domaincontroler "Do not enable any of the inputs during the installation". So i left on the last installation page all unchecked (no eventlogs, no AD monitoring, all unchecked). Is this right ? Bedause when i do that i cannot get any Faled Logon Data within the Active Directory APP. The ldap stuff is working fine, so i can see the green light and domain names and servernames within the Active Directory APP. What i am doing wrong ? Is it right that i do not need any Eventlogs separately configured at the Universal Forwarder to have those Failed logon Data ?

Thanks and best regards

Dave

Tags (1)
0 Karma

davidbaier
New Member

So, i will answer myself after some more investigation.

It seems on the Univeral Forwarder the Security logs needs to be enabled, so a inputs.conf needs to be copied to the following path: C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkTAwindows\local

with the following setting: [WinEventLog://Security] disabled = 0

That should do the trick, at least it is working for me now.

Dave

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...