All Apps and Add-ons

Splunk App for Windows Infrastructure: I am receiving Windows event logs, but why am I not getting anything related to Active Directory?

j666gak
Communicator

I have been asked to try and setup the Windows Infrastructure app, after a contractor had been in and left the instance in a worse state than when he started.

I keep getting the error below. I have a feeling it is something to do with LDAP or Powershell? I have researched as much as I can run the lookup rebuild option within the app, checked configuration/permissions 100 times. I am getting Windows event logs from the Domain Controllers but nothing related to Active Directory.

Would really appreciate any help please.

alt text

0 Karma

brooklynotss
Path Finder

I had almost the exact same problem with the same lookup tables in the errors. For me it was a Windows NTFS permissions issue on the server. I turned on enable inheritance (not sure why it wasn't on) and reset all permissions below that for the app. To clarify - this was on the splunk_app_windows_infrastructure folder in the Splunk/etc/apps folder. I also needed to the same for the Splunk_TA_windows

Also it's possible that when installing the app the default lookup table files didn't all copy down, so re-download from the splunk site (extract it) and you can just compare what lookup files are in the default install and what made it into your folder.

0 Karma

juvetm
Communicator

hi j666gak
it look as if you are having a problem on setup Splunk App for Windows Infrastructure: i forward you a documentation i think this wll help so your problem waiting to hear from you
http://docs.splunk.com/Documentation/MSApp/1.0.2

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...