Getting Data In

MS security integration with splunk

pavithra
Explorer

Hi All,

Data is not getting indexed after adding the conf

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Data will not be indexed automatically after adding the add-on.  Inputs must be configured so the add-on knows where to find the data.  See https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Configure

---
If this reply helps you, Karma would be appreciated.
0 Karma

pavithra
Explorer

Hi ,

I have added the config details already  , still data is not coming

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Typical GDI troubleshooting steps include:

  1. Verify the input configuration, including the URL and credentials.
  2. Verify the Splunk server running the add-on can connect to the MS server.  Use curl or a similar tool.
  3. Check splunkd.log for related messages.
  4. Check the MS logs for related messages.
  5. If you're using Splunk search to see if data is coming in then double-check the SPL.  Verify the index name.  Try specifying latest=+1y to account for timestamp errors.
---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...