Getting Data In

Active Directory monitor not enumerating existing objects

erga00
Path Finder

I've enabled the Active Directory monitoring module. I'm getting events as objects are modified but I would expect that there would be an initial scan of all objects so that entries for changed objects can be compared to their original value. Another useful byproduct of scanning all objects is that you can then add useful data like department, address, etc to search results.

The documentation doesn't mention anything about it and there isn't anything in the specs for admon.conf so this might be an enhancement request but I thought I'd ask in case someone else has gotten it to work.

I'm running 4.1.2 by the way.

EDIT:
I've confirmed that this bug is fixed in 4.1.4.

Tags (2)
1 Solution

the_wolverine
Champion

Yes, unfortunately, this is a bug in ADMonitor. It'll be fixed in 4.1.4.

ADMonitor does not index all baseline events (SPL-32393)

View solution in original post

0 Karma

the_wolverine
Champion

Yes, unfortunately, this is a bug in ADMonitor. It'll be fixed in 4.1.4.

ADMonitor does not index all baseline events (SPL-32393)

0 Karma

erga00
Path Finder

Thanks. Is there an ETA on 4.1.4?

0 Karma
Get Updates on the Splunk Community!

Security Professional: Sharpen Your Defenses with These .conf25 Sessions

Sooooooooooo, guess what. .conf25 is almost here, and if you're on the Security Learning Path, this is your ...

First Steps with Splunk SOAR

Our first step was to gather a list of the playbooks we wanted and to sort them by priority.  Once this list ...

How To Build a Self-Service Observability Practice with Splunk Observability Cloud

If you’ve read our previous post on self-service observability, you already know what it is and why it ...