Getting Data In

MS security integration with splunk

pavithra
Explorer

Hi All,

Data is not getting indexed after adding the conf

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Data will not be indexed automatically after adding the add-on.  Inputs must be configured so the add-on knows where to find the data.  See https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Configure

---
If this reply helps you, Karma would be appreciated.
0 Karma

pavithra
Explorer

Hi ,

I have added the config details already  , still data is not coming

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Typical GDI troubleshooting steps include:

  1. Verify the input configuration, including the URL and credentials.
  2. Verify the Splunk server running the add-on can connect to the MS server.  Use curl or a similar tool.
  3. Check splunkd.log for related messages.
  4. Check the MS logs for related messages.
  5. If you're using Splunk search to see if data is coming in then double-check the SPL.  Verify the index name.  Try specifying latest=+1y to account for timestamp errors.
---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...