Splunk ITSI

How to import Active Directory logs from another Splunk app into ITSI?

mstrzelecki
New Member

We just installed ISIT, and we're also using an app for AD object collection (MS Windows AD Objects ). I'm wondering it's it's possible to configure ISIT to use some of that existing AD data already collected? Also I was hoping to avoid having two AD related apps that might be pulling duplicate data from all Windows machines.

Labels (2)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @mstrzelecki,

You can try using the ITSI Content Packs (https://splunkbase.splunk.com/app/5391/) and try configuring the same for AD analysis. There are multiple content packs for different purposes. You can find the description related to content packs here - https://docs.splunk.com/Documentation/ContentPackApp/1.5.0/Overview/Overview#:~:text=for%20Content%2...

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...