Figured it out. Silly mistake of forgetting about script running in a different shell that may or may not have environmental variables for proxy.
... View more
Using the details in the cisco umbrella add-on for splunk. The pull-umbrella-logs.sh runs fine manually as the user, splunk. The sync will connect and pull logs with no issue. However, when left to run automated via splunk local inputs.conf. It cannot connect and fails to ingest any data. Splunkd log entry: ERROR ExecProcessor - message from "/opt/splunk/etc/apps/TA-cisco_umbrella/bin/pull-umbrella-logs.sh" fatal error: Could not connect to the endpoint URL As far as I can tell, splunk should be the using the same user (splunk) in order to run the script automatically. What might I be missing?
... View more
Yes, Currently, looking into the inputs.conf file from the TA-WIndows, As there are monitors that are disabled such as Directory service and File Replication service. If enabled, would that fix the problem?
... View more
The universal forwarder on the domain controller does not have SA-ldapsearch, only app deployed is TA-windows. SA-ldapsearch is only on the search head.
... View more
Domain controllers have a forwarder with the TA-Windows deployed via server class. Splunk App for Windows Infrastruture on the search head. We get wineventlog, some AD user record changes, logins, etc. However, Things like domain controller health and OU, nor domain drop downs in some dashboards are not populating. During the detect features configuration, Domains, Domain Controllers, and DNS do not get detected.
... View more