Getting Data In

Active Directory inputs missing SYNC event types after 6.2.1 upgrade?

mcrawford44
Communicator

As the question above states;

Since the 6.2.1 update of Splunk, our active directory inputs are no longer gathering 'admonEventType=Sync' events.

Sync events are the main meat of the AD indexes, containing the actual listing for objects.

Our last _time entry is 12/16/2014 around 10am, immediately after the 6.2.1 update.

The other 3 admonEventTypes are still collected. Start, Scheme, update.

I have recreated the inputs on 2 servers in different location, and the same behavior remains. Only 3 of the event types are being collected.

corey_dick
Path Finder

The solution is to remove the following line from the admon stanza in inputs.conf file in the system\default folder:

baseline=0

Adding baseline=1 to the inputs.conf in the system\local folder has no effect from what I could see. This issue effects all versions of 6.2 and 6.3.

0 Karma

mcrawford44
Communicator

Splunk support was able to replicate this bug and have submitted a ticket; SPL-104212

Awaiting response, and I will post any remediation steps here.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...