All Apps and Add-ons

TA for Windows AD

knewter
Engager

Hi everyone, Splunk newbie here. I'm currently trying to install the Splunk App for Active Directory version 1.2 and I wanted to make sure I understood the steps for configuring the Universal forwarder. Do I need to install the Splunk App for AD on the universal forwarder or just the Technology Add On that came with the app? Do I need to do any additional configuration at that point?

Thanks

0 Karma

bmacias84
Champion

keep in mind most apps in splunk base are templates and require some customization. This becomes more important as you begin layering apps.

knewter
Engager

Thanks for your quick response I was a little confused by the documentation.

Basically I would copy over the correct TAs to the \SplunkUniversalForwarder\etc\apps folder and If I'm happy with the defaults then I'm done.

0 Karma

gfuente
Motivator

Hello

You only need to install the full app in the Splunk server. You have to install the TA on top of the universal forwarder.

Regards

0 Karma

malmoore
Splunk Employee
Splunk Employee

If you could tell me where you found the documentation confusing, that would be most helpful.

Remember also that you need to install the Splunk TA for Windows as well as the Splunk App for Active Directory helper TAs for the version of Windows Server that the domain controllers and DNS servers in your environment run.

http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/Deploymentprocess#x3._Install_a...

gfuente
Motivator

That´s it

You´ll need to restart the UF, and maybe set to enable some inputs, that may come disabled by default

Regards

0 Karma

knewter
Engager

Thanks for your quick response I was a little confused by the documentation.

Basically I would copy over the correct TAs to the \SplunkUniversalForwarder\etc\apps folder and If I'm happy with the defaults then I'm done.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...