- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to import Active Directory logs from another Splunk app into ITSI?
mstrzelecki
New Member
04-04-2022
08:22 AM
We just installed ISIT, and we're also using an app for AD object collection (MS Windows AD Objects ). I'm wondering it's it's possible to configure ISIT to use some of that existing AD data already collected? Also I was hoping to avoid having two AD related apps that might be pulling duplicate data from all Windows machines.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
tshah-splunk

Splunk Employee
04-04-2022
10:05 AM
Hey @mstrzelecki,
You can try using the ITSI Content Packs (https://splunkbase.splunk.com/app/5391/) and try configuring the same for AD analysis. There are multiple content packs for different purposes. You can find the description related to content packs here - https://docs.splunk.com/Documentation/ContentPackApp/1.5.0/Overview/Overview#:~:text=for%20Content%2....
---
If you find the answer helpful, an upvote/karma is appreciated
If you find the answer helpful, an upvote/karma is appreciated
