Where is this error coming from? or is this problem within the AD app directory or something with my central splunk server?
It's something with your AD app install.
In default/transforms.conf, there is a stanza for GroupType - it basically converts the event type into a field GroupType that contains Security or Distribution. This is backed by a CSV file in lookups/
By default, this happens on your search head and it is passed down to indexers in the replication bundle if you have a separate indexer. However, it should just automatically be there. So, I believe the issue is in your install.
It's something with your AD app install.
In default/transforms.conf, there is a stanza for GroupType - it basically converts the event type into a field GroupType that contains Security or Distribution. This is backed by a CSV file in lookups/
By default, this happens on your search head and it is passed down to indexers in the replication bundle if you have a separate indexer. However, it should just automatically be there. So, I believe the issue is in your install.
It is in the AD app, could it be something with the actual csv file?
http://www.freeimagehosting.net/s86fw
Make sure the GroupType lookup is exported properly (go into Manager->Lookups and export it to system)
Actually this error is coming up in every app that I have not just the AD app which I got working.
Read the documentation on http://docs.splunk.com for detailed instructions on how to install the AD app.
Ok I'll go back through the install. Also would there happen to be a video or better reference to deploying splunk app for AD? I've been through all the documents on splunk base as well as the readme within the app multiple times and still can't get it to work.