All Apps and Add-ons

TA for Windows AD

knewter
Engager

Hi everyone, Splunk newbie here. I'm currently trying to install the Splunk App for Active Directory version 1.2 and I wanted to make sure I understood the steps for configuring the Universal forwarder. Do I need to install the Splunk App for AD on the universal forwarder or just the Technology Add On that came with the app? Do I need to do any additional configuration at that point?

Thanks

0 Karma

bmacias84
Champion

keep in mind most apps in splunk base are templates and require some customization. This becomes more important as you begin layering apps.

knewter
Engager

Thanks for your quick response I was a little confused by the documentation.

Basically I would copy over the correct TAs to the \SplunkUniversalForwarder\etc\apps folder and If I'm happy with the defaults then I'm done.

0 Karma

gfuente
Motivator

Hello

You only need to install the full app in the Splunk server. You have to install the TA on top of the universal forwarder.

Regards

0 Karma

malmoore
Splunk Employee
Splunk Employee

If you could tell me where you found the documentation confusing, that would be most helpful.

Remember also that you need to install the Splunk TA for Windows as well as the Splunk App for Active Directory helper TAs for the version of Windows Server that the domain controllers and DNS servers in your environment run.

http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/Deploymentprocess#x3._Install_a...

gfuente
Motivator

That´s it

You´ll need to restart the UF, and maybe set to enable some inputs, that may come disabled by default

Regards

0 Karma

knewter
Engager

Thanks for your quick response I was a little confused by the documentation.

Basically I would copy over the correct TAs to the \SplunkUniversalForwarder\etc\apps folder and If I'm happy with the defaults then I'm done.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...