All Apps and Add-ons

Data not displayed for App:Splunk App for Active Directory and 'Security Dashabord

sat94541
Communicator

No Data displayed for App:Splunk App for Active Directory and 'Security Dashabord' Views ‘Failed Logon over Time’, ‘Failed logon by Reason’ , ‘Failed logons by IP Address’ and ‘failed logon by User'

I have installed -Splunk_for_ActiveDirectory.

1) Domain Controller has Universal Forwarder (Version=6.0.2)
OS Version : OS Name Microsoft(R) Windows(R) Server 2003, Standard Edition (Version 5.2.3790 Service Pack 2 Build 3790)
Case:163029:Splunk 6 upgrade broke UF forwarding
Splunk Universal Version : 6.0.2
TA installed :
-Splunk_TA_windows (version = 4.6.4)
-SA-ldapsearch (version = 1.1.10 )
-TA-DNSServer-NT5 (version=1.2.2)
-TA-DomainController-NT5 (version=1.2.2)

2) The Indexer cum Search Head
OS Version : Linux
Splunk Version : 6.0.1
App and TA :
-Splunk_for_ActiveDirectory (version = 1.2.2)
-SA-ldapsearch (version = 1.1.11)
-Splunk_for_Exchange (version = 2.1.2)
-Splunk_TA_windows (version = 4.6.

*Issue ::::No Data is displayed for 'App:Splunk App for Active Directory ' and 'Security'Dashabord : User Long on Failure. See screenshot below

0 Karma

rbal_splunk
Splunk Employee
Splunk Employee

This behavior has been identified as bug -- MSAPP-1114:Inconsistent extraction between NT5 and NT6 for failed logins.

Expected to be fixed by Windows TA 4.7.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...