Getting Data In

Admon duplicating logs

TheCityRich
New Member

Hey everyone, I'm having some small issues with my new Splunk setup in regards to AD logging. I have a few domain controllers that I just setup to receive updates from our Deployment Server (Windows_TA app). My original issue was figuring out how to get admon logs to go to our index=msad rather than the default index=main. I was able to partially fix that issue by modifying the inputs.conf file in the deployment-app. Now the logs are being sent to the correct index=msad.

However, admon logs are also still being sent to index=main. We now have admon data duplication between 2 indexes. Does anyone have any ideas on how to get the DC's to stop sending admon logs to index=main? Preferably some configuration i could push from our Deployment Server? This is an example of a stanza in our inputs.conf that is being pushed to the DC's from Deployment Server:

 

[admon://ADMonitoring]

targetDc = DC102

monitorSubtree = 1

baseline = 0

index = msad

disabled = false

Labels (2)
0 Karma

codebuilder
Influencer

When you push out an app/configs from the DS they get merged into the "default" directory on your forwarders. If you modify it manually or through the web ui those are stored under "local". My guess is that you have a version of inputs.conf under the local directory. Delete that file and cycle the service.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...