All Apps and Add-ons

Data not displayed for App:Splunk App for Active Directory and 'Security Dashabord

sat94541
Communicator

No Data displayed for App:Splunk App for Active Directory and 'Security Dashabord' Views ‘Failed Logon over Time’, ‘Failed logon by Reason’ , ‘Failed logons by IP Address’ and ‘failed logon by User'

I have installed -Splunk_for_ActiveDirectory.

1) Domain Controller has Universal Forwarder (Version=6.0.2)
OS Version : OS Name Microsoft(R) Windows(R) Server 2003, Standard Edition (Version 5.2.3790 Service Pack 2 Build 3790)
Case:163029:Splunk 6 upgrade broke UF forwarding
Splunk Universal Version : 6.0.2
TA installed :
-Splunk_TA_windows (version = 4.6.4)
-SA-ldapsearch (version = 1.1.10 )
-TA-DNSServer-NT5 (version=1.2.2)
-TA-DomainController-NT5 (version=1.2.2)

2) The Indexer cum Search Head
OS Version : Linux
Splunk Version : 6.0.1
App and TA :
-Splunk_for_ActiveDirectory (version = 1.2.2)
-SA-ldapsearch (version = 1.1.11)
-Splunk_for_Exchange (version = 2.1.2)
-Splunk_TA_windows (version = 4.6.

*Issue ::::No Data is displayed for 'App:Splunk App for Active Directory ' and 'Security'Dashabord : User Long on Failure. See screenshot below

0 Karma

rbal_splunk
Splunk Employee
Splunk Employee

This behavior has been identified as bug -- MSAPP-1114:Inconsistent extraction between NT5 and NT6 for failed logins.

Expected to be fixed by Windows TA 4.7.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...