Before troubleshooting, ensure the following:
ADAudit Plus is able to establish communication with the Splunk server on the configured HTTP collector port.
The correct authentication token is provided in the Splunk configuration page.
Data being forwarded might not be in the required Splunk format.
Click on Settings → Data Inputs → HTTP Event Collector.
Click New Token and provide a name (preferably "ADAuditPlus"). Leave other settings as default unless customization is required.
After saving, an authentication token will be generated. This token must be provided in the ADAudit Plus configuration.
Under Global Settings in the HTTP Event Collector page, enable All tokens.
You may customize the HTTP port number and SSL settings as required in Global Settings.
Tick the Enable checkbox and select the Splunk radio button.
Enter the Splunk Server name and ensure that it is reachable from the ADAudit Plus Server.
Provide the Splunk HTTP Event Collector port number and protocol.
Enter the HTTP Event Collector token generated in Splunk for ADAudit Plus.
After saving, choose the categories to forward.
If syntax does not match "Splunk" format or files are empty, delete them and restart ADAudit Plus service.
Example of correct Splunk syntax:
{"time":1624534057,"event":{"DOMAIN":"ADAuditPlus Authentication","Category":"ADAPTechnicianAudit","ACCOUNT_ID":"1","LOGIN_ID":"1","CLIENT_IP_ADDRESS":"127.0.0.1","EVENT_TYPE":"8","USER_ID":"1","ADDITIONAL_INFO":"-","CLIENT_HOST_NAME":"ADAudit Plus Server","ACTION_ID":"4","ACTION_CATEGORY":"Admin","TIME_GENERATED":"1624534057","ACCESS_TYPE":"8","FORMAT_MESSAGE":"Successfully saved SIEM Integration Categories data","SESSION_ID":"20409","LOGIN_NAME":"admin","SEVERITY":"2"}}
General Troubleshooting for Log Forwarding