Getting Data In

MS security integration with splunk

pavithra
Explorer

Hi All,

Data is not getting indexed after adding the conf

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Data will not be indexed automatically after adding the add-on.  Inputs must be configured so the add-on knows where to find the data.  See https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Configure

---
If this reply helps you, Karma would be appreciated.
0 Karma

pavithra
Explorer

Hi ,

I have added the config details already  , still data is not coming

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Typical GDI troubleshooting steps include:

  1. Verify the input configuration, including the URL and credentials.
  2. Verify the Splunk server running the add-on can connect to the MS server.  Use curl or a similar tool.
  3. Check splunkd.log for related messages.
  4. Check the MS logs for related messages.
  5. If you're using Splunk search to see if data is coming in then double-check the SPL.  Verify the index name.  Try specifying latest=+1y to account for timestamp errors.
---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...