Getting Data In

How to debug evt_resolve_ad_obj on a universal forwarder?

Ed_Alias
Path Finder

Hi,

I am trying to debug evt_resolve_ad_obj not working properly?

How do I enable debug to see wich Domain Controller is being contacted, and see the answer from the DC?

i am on UF 6.2.3 on windows server 2008R2.

0 Karma

dstaulcu
Builder

Hello

For the fact that you are checking on the DC used by a UF, I suspect you have stumbled across a bug I struggled with for a while..

Somewhere between version 6.0 and 6.0.3, a bug was introduced causing the universal to communicate with the PDC of your domain (instead of nearest DC) regardless of whether evt_resolve_ad_obj was enabled or disabled for each wineventlog based input. I submitted an SPL for this issue and the issue was corrected in version 6.3.0.

http://answers.splunk.com/answers/171507/universal-forwarder-wineventlog-handler-affinity-f.html

0 Karma

woodcock
Esteemed Legend

According to the dox here:

http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/Monitorwindowsdata

If you discover that Splunk is not translating SIDs properly, review splunkd.log for clues on what the problem might be.
0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...