Getting Data In

Active Directory monitor not enumerating existing objects

erga00
Path Finder

I've enabled the Active Directory monitoring module. I'm getting events as objects are modified but I would expect that there would be an initial scan of all objects so that entries for changed objects can be compared to their original value. Another useful byproduct of scanning all objects is that you can then add useful data like department, address, etc to search results.

The documentation doesn't mention anything about it and there isn't anything in the specs for admon.conf so this might be an enhancement request but I thought I'd ask in case someone else has gotten it to work.

I'm running 4.1.2 by the way.

EDIT:
I've confirmed that this bug is fixed in 4.1.4.

Tags (2)
1 Solution

the_wolverine
Champion

Yes, unfortunately, this is a bug in ADMonitor. It'll be fixed in 4.1.4.

ADMonitor does not index all baseline events (SPL-32393)

View solution in original post

0 Karma

the_wolverine
Champion

Yes, unfortunately, this is a bug in ADMonitor. It'll be fixed in 4.1.4.

ADMonitor does not index all baseline events (SPL-32393)

0 Karma

erga00
Path Finder

Thanks. Is there an ETA on 4.1.4?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...