Getting Data In

MS security integration with splunk

pavithra
Explorer

Hi All,

Data is not getting indexed after adding the conf

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Data will not be indexed automatically after adding the add-on.  Inputs must be configured so the add-on knows where to find the data.  See https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Configure

---
If this reply helps you, Karma would be appreciated.
0 Karma

pavithra
Explorer

Hi ,

I have added the config details already  , still data is not coming

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Typical GDI troubleshooting steps include:

  1. Verify the input configuration, including the URL and credentials.
  2. Verify the Splunk server running the add-on can connect to the MS server.  Use curl or a similar tool.
  3. Check splunkd.log for related messages.
  4. Check the MS logs for related messages.
  5. If you're using Splunk search to see if data is coming in then double-check the SPL.  Verify the index name.  Try specifying latest=+1y to account for timestamp errors.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

New Case Study: How LSU’s Student-Powered SOCs and Splunk Are Shaping the Future of ...

Louisiana State University (LSU) is shaping the next generation of cybersecurity professionals through its ...

Splunk and Fraud

Join us on November 13 at 11 am PT / 2 pm ET!Join us for an insightful webinar where we delve into the ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...