Help me out with this question...
Can AD be monitored by theSplunk enterprise which is running on linux..? I refered to thesplunk documentation of
https://docs.splunk.com/Documentation/Splunk...
Splunkbase says SplunkAdd-onforMicrosoftActiveDirectory is complaint with CIM VERSIONS 4.0, 3.0 ( https://splunkbase.splunk.com/app/3207/ ), but I cannot find the documentation like other Splunk...
what should be the best practice to collect data from below sources . any recommendation ?
Domain Controller (ActiveDirectory)
ePO Virus Scan
ePO DLP
FireEye EX
FireEye NX
Check Point F...
We have an issue with theMicrosoft Azure ActiveDirectory Reporting Add-onforSplunk where it's not retrieving all the signin events.
We currently have our interval set at 60 seconds. We can t...
...ffice-365-management-api/office-365-management-activity-api-reference
I want to collect similar data from a local exchange server now but I don't know the logs.
TheSplunkAdd-onforMicrosoft...
One question about “Microsoft Office 365 App forSplunk”.
Can it use log data from “Microsoft Azure ActiveDirectoryAdd-onforSplunk” forthe Azure AD logs?
Or does it can only get logs d...
...nd is receiving data
2 Activedirectory Baseline is Working...sourcetype="ActiveDirectory" admonEventType="Sync"
3 We have installed AddOnforMicrosoftActiveDirectoryon 1 DC that is sending the...
Logs from Microsoft Azure ActiveDirectory Reporting Add-onforSplunk are in Chinese. Tried encoding it by setting the CHARSET value to AUTO as well as GB18030 in props.conf file. But still the s...
.... Once that was changed we could launch Splunk, and then received the errors.
Originally we were using ADFS for SSO and it worked fine, but now when going to the site we get the error, "IDP f...