Hi guys, i've been trying to configure the Splunk app for windows infrastructure and for that I've previously installed the addon you see on the subject. But when I'm running the data check I see that the ActiveDirectory* sourcetype that I need to see , is not returning any events. See below:
What could this be?
Thanks in advance!
I had the same problem last week (still on my first deployment project of Splunk), and once I went through the inputs it all flowed.
I had better results too when I specified the indexes for each sourcetype - had been getting some results into main for some instead of msad until then.
check your inputs.conf In Splunk Add-On for Windows - likely you haven't enabled the desired types so the forwarders aren't sending it. Remember it'll probably need to be deployed to your universal forwarders.