I've got a single instance splunk environment for testing and have it working just fine, but don't have a deployment server. I need to get Active Directory data into splunk and have everything configured, but I'm not sure what to do regarding deploying the Splunk Add-on for Microsoft Active Directory. Is there a way to configure the necessary apps/settings for a UF running on a DC without a DS?
Yes,
place the app in /etc/apps on your forwarder, restart the forwarder and go up and away!
p.s. you can use your single splunk as a deployment server if you wish to
hope it helps