Hi,
I have installed Splunk App for Windows Infrastructure with Splunk Add-on for Microsoft Windows v7
This article says that Splunk Add-on for Microsoft Active Directory has merged with Splunk Add-on for Microsoft Windows v6 and above.
Documentation/MSApp/2.0.0/MSInfra/DeploytheSplunkAdd-onsforActiveDirectory
Do I still need to install Splunk Add-on for Microsoft Active Directory on the forwarders on the domain controllers? If so I assume I need to add the SA-ldapsearch folder to my distribution server.
I have disabled Splunk Add-on for Microsoft Active Directory v1 as I didn't think I would need this anymore?
I have these Apps installed. Does this look correct?
Any help would much appreciated.