Getting Data In

How to debug evt_resolve_ad_obj on a universal forwarder?

Ed_Alias
Path Finder

Hi,

I am trying to debug evt_resolve_ad_obj not working properly?

How do I enable debug to see wich Domain Controller is being contacted, and see the answer from the DC?

i am on UF 6.2.3 on windows server 2008R2.

0 Karma

dstaulcu
Builder

Hello

For the fact that you are checking on the DC used by a UF, I suspect you have stumbled across a bug I struggled with for a while..

Somewhere between version 6.0 and 6.0.3, a bug was introduced causing the universal to communicate with the PDC of your domain (instead of nearest DC) regardless of whether evt_resolve_ad_obj was enabled or disabled for each wineventlog based input. I submitted an SPL for this issue and the issue was corrected in version 6.3.0.

http://answers.splunk.com/answers/171507/universal-forwarder-wineventlog-handler-affinity-f.html

0 Karma

woodcock
Esteemed Legend

According to the dox here:

http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/Monitorwindowsdata

If you discover that Splunk is not translating SIDs properly, review splunkd.log for clues on what the problem might be.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...