All Apps and Add-ons

Does Splunk for MS AD Objects 3.2.9 work on Splunk Enterprise 8.0.x?



Has anyone run the MS Windows AD Objects version 3.2.9 APP on Splunk Enterprise 8.0.x?
If so, how was your experience... did you get it to work... did you have to do anything special to get it working?

Any one know when might a version of the APP compatible with Splunk Enterprise 8.0.x be available?

Thanks in advance for your feedback.

0 Karma

Splunk Employee
Splunk Employee

Fyi, I just released an Update, version 4.0.3 that now fully supports Splunk Version 8.x.   Although 3.2.9 would work, the dashboards with the tabs had issues.   

FYI, Version 4.0.3 has a lot of changes, with the biggest part consisting of now using the KVstore vs csv lookups.   This was needed for scalability purposes, but does greatly improve performance with synchronizing the lookups (ie applying diffs vs full rebuilds) and with performing lookups (Ex. ...| lookup lookup_usr AS src_user OUTPUT cn AS Admin_User).   I also now use macro's for pointing to the indexes, instead of eventtypes.   

If you are upgrading, or doing a new install, you will need to walk through the Configuration - Getting Data In dashboard to verify/update the appropriate macros and migrate/build the new kvstore lookups.  

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...