All Apps and Add-ons

Splunk App for Active Directory - Universal Forwarder 5.0 support

yrajah
Explorer

Hi,
Just noticed that "The Splunk App for Active Directory does not currently work with Splunk universal forwarder versions 5.0 and later".

Does anybody know when it will be supported?

Many thanks.

0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

To clarify - it will be supported in the next release. If you want the TA's to support the Splunk Universal Forwarder 5.0, then do the following for each TA:

1) Go into the TA directory/defaults
2) Append the contents of perfmon.conf to inputs.conf
3) Edit inputs.conf and do a global search-and-replace on PERFMON: - replace it with perfmon://

Note that case is important here. Once that is done, then you will be ready to go. Do this in defaults instead of the normal local area because then, when the upgrade happens, your changes will be replaced with the "official" changes.

View solution in original post

ahall_splunk
Splunk Employee
Splunk Employee

To clarify - it will be supported in the next release. If you want the TA's to support the Splunk Universal Forwarder 5.0, then do the following for each TA:

1) Go into the TA directory/defaults
2) Append the contents of perfmon.conf to inputs.conf
3) Edit inputs.conf and do a global search-and-replace on PERFMON: - replace it with perfmon://

Note that case is important here. Once that is done, then you will be ready to go. Do this in defaults instead of the normal local area because then, when the upgrade happens, your changes will be replaced with the "official" changes.

ahall_splunk
Splunk Employee
Splunk Employee

Not as yet.

0 Karma

yrajah
Explorer

Thank you for the reply. Is there a scheduled date for the next release?

0 Karma

jgedeon120
Contributor

Yrajah,

I reached out to the microsoft team yesterday and they are currently working on the issues. Hopefully it will be sometime soon. They did not give a date yet. You can subscribe to the app/project and be notified of updates.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...