All Apps and Add-ons

Splunk App for Active Directory - Universal Forwarder 5.0 support

yrajah
Explorer

Hi,
Just noticed that "The Splunk App for Active Directory does not currently work with Splunk universal forwarder versions 5.0 and later".

Does anybody know when it will be supported?

Many thanks.

0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

To clarify - it will be supported in the next release. If you want the TA's to support the Splunk Universal Forwarder 5.0, then do the following for each TA:

1) Go into the TA directory/defaults
2) Append the contents of perfmon.conf to inputs.conf
3) Edit inputs.conf and do a global search-and-replace on PERFMON: - replace it with perfmon://

Note that case is important here. Once that is done, then you will be ready to go. Do this in defaults instead of the normal local area because then, when the upgrade happens, your changes will be replaced with the "official" changes.

View solution in original post

ahall_splunk
Splunk Employee
Splunk Employee

To clarify - it will be supported in the next release. If you want the TA's to support the Splunk Universal Forwarder 5.0, then do the following for each TA:

1) Go into the TA directory/defaults
2) Append the contents of perfmon.conf to inputs.conf
3) Edit inputs.conf and do a global search-and-replace on PERFMON: - replace it with perfmon://

Note that case is important here. Once that is done, then you will be ready to go. Do this in defaults instead of the normal local area because then, when the upgrade happens, your changes will be replaced with the "official" changes.

ahall_splunk
Splunk Employee
Splunk Employee

Not as yet.

0 Karma

yrajah
Explorer

Thank you for the reply. Is there a scheduled date for the next release?

0 Karma

jgedeon120
Contributor

Yrajah,

I reached out to the microsoft team yesterday and they are currently working on the issues. Hopefully it will be sometime soon. They did not give a date yet. You can subscribe to the app/project and be notified of updates.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...