Hi, We are trying to setup splunk app for Windows ad object monitoring as per MS Windows AD Objects | Splunkbase. Here we already have Windows TA Infrastructure app configured and sending logs to separate indexes rather than default mentioned in the app. Whenever I provide that index name in macro and run autocheck, it is not able to detect the data in that index. When I search that index in splunk search, I can see data coming into that index. We have data configured in xml based log format instead of classic ones. We have following setup. catchvjay_0-1612883767419.png What could be the reason this app is not able to detect the data?
... View more