Getting Data In

MS security integration with splunk

pavithra
Explorer

Hi All,

Data is not getting indexed after adding the conf

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Data will not be indexed automatically after adding the add-on.  Inputs must be configured so the add-on knows where to find the data.  See https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Configure

---
If this reply helps you, Karma would be appreciated.
0 Karma

pavithra
Explorer

Hi ,

I have added the config details already  , still data is not coming

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Typical GDI troubleshooting steps include:

  1. Verify the input configuration, including the URL and credentials.
  2. Verify the Splunk server running the add-on can connect to the MS server.  Use curl or a similar tool.
  3. Check splunkd.log for related messages.
  4. Check the MS logs for related messages.
  5. If you're using Splunk search to see if data is coming in then double-check the SPL.  Verify the index name.  Try specifying latest=+1y to account for timestamp errors.
---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...