Getting Data In

Active Directory not send logs for Splunk

mlog
New Member

Hello,

I am using splunk enterprise on linux server. I want to monitor active directory logs. I installed the universal splunk forwarder on windows server and configuring ports and accounts.

I am using splunk enterprise and have not received logs from the active windows directory.

I installed addons for prerequisites.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi mlog,
you have to use the correct Technical AddOns (TAs).

See the documentation of Splunk App for Windows Infrastructure at https://docs.splunk.com/Documentation/MSApp/latest/MSInfra/AbouttheSplunkAppforMSInfrastructure to know which TAs to deploy and what to configure on Domain Controllers.

Bye.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi mlog,
if you're satisfied by this answer, please accept and/or upvote it.

Bye, see next time.
Giuseppe

0 Karma

lakshman239
Influencer

Have you installed https://splunkbase.splunk.com/app/3207/ and enabled the required inputs?
check if there is any connectivity issue between the forwarder and indexer?
Are you getting _internal logs from the active directory server/windows?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...