All Apps and Add-ons

Single Instance Splunk, no DS, deploy AD add-on

msaz
Path Finder

I've got a single instance splunk environment for testing and have it working just fine, but don't have a deployment server. I need to get Active Directory data into splunk and have everything configured, but I'm not sure what to do regarding deploying the Splunk Add-on for Microsoft Active Directory. Is there a way to configure the necessary apps/settings for a UF running on a DC without a DS?

0 Karma

adonio
Ultra Champion

Yes,
place the app in /etc/apps on your forwarder, restart the forwarder and go up and away!

p.s. you can use your single splunk as a deployment server if you wish to

hope it helps

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...