Getting Data In

Active Directory APP - no Failed Logon Data

davidbaier
New Member

Hi, i need some help with the Active Directory APP installation because i cannot get any Failed Logon Data within the APP.

i am using the Trial Version of Splunk
- we have 1 Unix Indexer
- we have 1 Windows 2008 R2 Domaincontroller (Universal Client).

I installed on the Indexer:
Active Directory APP
(deployeed to the Domaincontroller TA-DomainController-NT6)
(deployeed to the Domaincontroller TA-DNSServer-NT6)
SA-ldapsearch and configured it, it works fine
Splunk Ad-on for Windows
(deployeed it to the Domaincontroller)
Sideview

On the Domaincontroller i installed:
Universal Forwarder
deployeed the TA-Domaincontroller-NT6 and DNSServer-NT6 and the Add-on for Windows

Now my question, the documentation says that when installing the Universal Forwarder on the domaincontroler "Do not enable any of the inputs during the installation". So i left on the last installation page all unchecked (no eventlogs, no AD monitoring, all unchecked). Is this right ? Bedause when i do that i cannot get any Faled Logon Data within the Active Directory APP. The ldap stuff is working fine, so i can see the green light and domain names and servernames within the Active Directory APP. What i am doing wrong ? Is it right that i do not need any Eventlogs separately configured at the Universal Forwarder to have those Failed logon Data ?

Thanks and best regards

Dave

Tags (1)
0 Karma

davidbaier
New Member

So, i will answer myself after some more investigation.

It seems on the Univeral Forwarder the Security logs needs to be enabled, so a inputs.conf needs to be copied to the following path: C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkTAwindows\local

with the following setting: [WinEventLog://Security] disabled = 0

That should do the trick, at least it is working for me now.

Dave

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...