Getting Data In

Splunk cloud and Microsoft Infrastructure

skeeter395
Observer

Hello All,

It is only Tuesday and it has been quite the journey. I have a splunk cloud instance. I logged a call and got the Splunk add-on for Microsoft Infrastructure installed. Went to configure it and found that I needed the Microsoft add-on for Active Directory also configured. So after reading the documentation:

https://docs.splunk.com/Documentation/SA-LdapSearch/3.0.1/User/ConfiguretheSplunkSupportingAdd-onfor...

I found that I need to configure the add-on for AD on a heavy forwarder on site. So the above link sent me to here:

https://docs.splunk.com/Documentation/SA-LdapSearch/3.0.1/User/ConfiguretheSplunkSupportingAdd-onfor...

Once at the above link everything starts to fall apart. The documentation style on the splunk site is so bad. Just link to link to link with not really good substance of data. The lines get blurred really quickly on what I need to do if I have Splunk cloud and if I have Splunk enterprise. Do we have a good guide on how to get these pieces working together? Sorry for sounding grumpy it has been an adventure.

 

Thanks,

Scott

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...