All Apps and Add-ons

Splunk App for Active Directory - Universal Forwarder 5.0 support

yrajah
Explorer

Hi,
Just noticed that "The Splunk App for Active Directory does not currently work with Splunk universal forwarder versions 5.0 and later".

Does anybody know when it will be supported?

Many thanks.

0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

To clarify - it will be supported in the next release. If you want the TA's to support the Splunk Universal Forwarder 5.0, then do the following for each TA:

1) Go into the TA directory/defaults
2) Append the contents of perfmon.conf to inputs.conf
3) Edit inputs.conf and do a global search-and-replace on PERFMON: - replace it with perfmon://

Note that case is important here. Once that is done, then you will be ready to go. Do this in defaults instead of the normal local area because then, when the upgrade happens, your changes will be replaced with the "official" changes.

View solution in original post

ahall_splunk
Splunk Employee
Splunk Employee

To clarify - it will be supported in the next release. If you want the TA's to support the Splunk Universal Forwarder 5.0, then do the following for each TA:

1) Go into the TA directory/defaults
2) Append the contents of perfmon.conf to inputs.conf
3) Edit inputs.conf and do a global search-and-replace on PERFMON: - replace it with perfmon://

Note that case is important here. Once that is done, then you will be ready to go. Do this in defaults instead of the normal local area because then, when the upgrade happens, your changes will be replaced with the "official" changes.

ahall_splunk
Splunk Employee
Splunk Employee

Not as yet.

0 Karma

yrajah
Explorer

Thank you for the reply. Is there a scheduled date for the next release?

0 Karma

jgedeon120
Contributor

Yrajah,

I reached out to the microsoft team yesterday and they are currently working on the issues. Hopefully it will be sometime soon. They did not give a date yet. You can subscribe to the app/project and be notified of updates.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...