Getting Data In

Active Directory APP - no Failed Logon Data

davidbaier
New Member

Hi, i need some help with the Active Directory APP installation because i cannot get any Failed Logon Data within the APP.

i am using the Trial Version of Splunk
- we have 1 Unix Indexer
- we have 1 Windows 2008 R2 Domaincontroller (Universal Client).

I installed on the Indexer:
Active Directory APP
(deployeed to the Domaincontroller TA-DomainController-NT6)
(deployeed to the Domaincontroller TA-DNSServer-NT6)
SA-ldapsearch and configured it, it works fine
Splunk Ad-on for Windows
(deployeed it to the Domaincontroller)
Sideview

On the Domaincontroller i installed:
Universal Forwarder
deployeed the TA-Domaincontroller-NT6 and DNSServer-NT6 and the Add-on for Windows

Now my question, the documentation says that when installing the Universal Forwarder on the domaincontroler "Do not enable any of the inputs during the installation". So i left on the last installation page all unchecked (no eventlogs, no AD monitoring, all unchecked). Is this right ? Bedause when i do that i cannot get any Faled Logon Data within the Active Directory APP. The ldap stuff is working fine, so i can see the green light and domain names and servernames within the Active Directory APP. What i am doing wrong ? Is it right that i do not need any Eventlogs separately configured at the Universal Forwarder to have those Failed logon Data ?

Thanks and best regards

Dave

Tags (1)
0 Karma

davidbaier
New Member

So, i will answer myself after some more investigation.

It seems on the Univeral Forwarder the Security logs needs to be enabled, so a inputs.conf needs to be copied to the following path: C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkTAwindows\local

with the following setting: [WinEventLog://Security] disabled = 0

That should do the trick, at least it is working for me now.

Dave

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...