Getting Data In

Active Directory monitor not enumerating existing objects

erga00
Path Finder

I've enabled the Active Directory monitoring module. I'm getting events as objects are modified but I would expect that there would be an initial scan of all objects so that entries for changed objects can be compared to their original value. Another useful byproduct of scanning all objects is that you can then add useful data like department, address, etc to search results.

The documentation doesn't mention anything about it and there isn't anything in the specs for admon.conf so this might be an enhancement request but I thought I'd ask in case someone else has gotten it to work.

I'm running 4.1.2 by the way.

EDIT:
I've confirmed that this bug is fixed in 4.1.4.

Tags (2)
1 Solution

the_wolverine
Champion

Yes, unfortunately, this is a bug in ADMonitor. It'll be fixed in 4.1.4.

ADMonitor does not index all baseline events (SPL-32393)

View solution in original post

0 Karma

the_wolverine
Champion

Yes, unfortunately, this is a bug in ADMonitor. It'll be fixed in 4.1.4.

ADMonitor does not index all baseline events (SPL-32393)

0 Karma

erga00
Path Finder

Thanks. Is there an ETA on 4.1.4?

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...