All Apps and Add-ons

No Data in Splunk App for Active Directory

jhutto
Explorer

I recently setup a trial Splunk server in my environment, and one of the compents I would like to try is the Splunk App for Active Directory. I also installed the prerequisite apps: Sideview Utils and Windows Technology Add-on.
For data inputs, I have Splunk monitoring the remote event logs on my domain controllers as well as a base DN in Active Directory. I've let it run for almost 24 hours, but there is no data displayed in the Splunk App for Active Directory. Using the built-in Search App, I can find account lockout events, failed logins, etc., but nothing is being displayed in the AD App.
I'm pretty new to Splunk, so I'm sure it's something obvious I've overlooked.

Thanks in advance for any help you can provide.

1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

The Splunk App for Active Directory requires that additional technology add-ons be placed on a Universal Forwarder on your Domain Controllers. The app requires that inventory information is retrieved from each domain controller, so it doesn't work with remote collection.

See the documentation on this app at http://docs.splunk.com

View solution in original post

ahall_splunk
Splunk Employee
Splunk Employee

The Splunk App for Active Directory requires that additional technology add-ons be placed on a Universal Forwarder on your Domain Controllers. The app requires that inventory information is retrieved from each domain controller, so it doesn't work with remote collection.

See the documentation on this app at http://docs.splunk.com

jhutto
Explorer

Thank you!

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

No. You need to install the Universal Forwarder on your Domain Controllers, configuring it to send events to your central splunk instance, and then install the Splunk_TA_windows and the appropriate Technology Add-ons in appserver/addons of the Splunk for Active Directory app.

Remote data collection is NOT supported with the Splunk for Active Directory app.

0 Karma

jhutto
Explorer

So I need to install that remote collection agent on my DCs?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...