Getting Data In

Active Directory monitor not enumerating existing objects

erga00
Path Finder

I've enabled the Active Directory monitoring module. I'm getting events as objects are modified but I would expect that there would be an initial scan of all objects so that entries for changed objects can be compared to their original value. Another useful byproduct of scanning all objects is that you can then add useful data like department, address, etc to search results.

The documentation doesn't mention anything about it and there isn't anything in the specs for admon.conf so this might be an enhancement request but I thought I'd ask in case someone else has gotten it to work.

I'm running 4.1.2 by the way.

EDIT:
I've confirmed that this bug is fixed in 4.1.4.

Tags (2)
1 Solution

the_wolverine
Champion

Yes, unfortunately, this is a bug in ADMonitor. It'll be fixed in 4.1.4.

ADMonitor does not index all baseline events (SPL-32393)

View solution in original post

0 Karma

the_wolverine
Champion

Yes, unfortunately, this is a bug in ADMonitor. It'll be fixed in 4.1.4.

ADMonitor does not index all baseline events (SPL-32393)

0 Karma

erga00
Path Finder

Thanks. Is there an ETA on 4.1.4?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...