Hi,
Just noticed that "The Splunk App for Active Directory does not currently work with Splunk universal forwarder versions 5.0 and later".
Does anybody know when it will be supported?
Many thanks.
To clarify - it will be supported in the next release. If you want the TA's to support the Splunk Universal Forwarder 5.0, then do the following for each TA:
1) Go into the TA directory/defaults
2) Append the contents of perfmon.conf to inputs.conf
3) Edit inputs.conf and do a global search-and-replace on PERFMON: - replace it with perfmon://
Note that case is important here. Once that is done, then you will be ready to go. Do this in defaults instead of the normal local area because then, when the upgrade happens, your changes will be replaced with the "official" changes.
To clarify - it will be supported in the next release. If you want the TA's to support the Splunk Universal Forwarder 5.0, then do the following for each TA:
1) Go into the TA directory/defaults
2) Append the contents of perfmon.conf to inputs.conf
3) Edit inputs.conf and do a global search-and-replace on PERFMON: - replace it with perfmon://
Note that case is important here. Once that is done, then you will be ready to go. Do this in defaults instead of the normal local area because then, when the upgrade happens, your changes will be replaced with the "official" changes.
Not as yet.
Thank you for the reply. Is there a scheduled date for the next release?
Yrajah,
I reached out to the microsoft team yesterday and they are currently working on the issues. Hopefully it will be sometime soon. They did not give a date yet. You can subscribe to the app/project and be notified of updates.