I've just setup Splunk App for Windows Infrastructure v1.4.2 (on Splunk v6.5.6) with Active Directory shipping in logs. Most of it seems to be working fine, except for pages that have the Domain drop down box don't work. I just get the message, Search produced no results.
Looking at the search for that drop down box, the first part of the command is | ad-domains . When I run that I get nothing back.
When I look up ad-domains macro, it starts with inputlookup DomainSelector. When I run that, it returns no results.
I checked, and DomainSelector.csv in the lookups folder does contain the correct data. And running |inputlookup DomainSelector.csv works as expected, returning the contents of the csv.
If I do |inputlookup EventCodes it works fine. The main difference I can find is in transforms.conf
[DomainSelector]
external_type = kvstore
collection = DomainSelector_collection
fields_list = host, DomainNetBIOSName, DomainDNSName, ForestName, Site
[EventCodes]
filename=EventCodes.csv
max_matches=1
DomainSelector is a collection, while EventCodes is just a .csv. This is going beyond my limited knowledge, so I'm hoping for some help. How do I get the inputlookup command to work for DomainSelector?
Thanks
... View more