All Apps and Add-ons

TA for Windows AD

knewter
Engager

Hi everyone, Splunk newbie here. I'm currently trying to install the Splunk App for Active Directory version 1.2 and I wanted to make sure I understood the steps for configuring the Universal forwarder. Do I need to install the Splunk App for AD on the universal forwarder or just the Technology Add On that came with the app? Do I need to do any additional configuration at that point?

Thanks

0 Karma

bmacias84
Champion

keep in mind most apps in splunk base are templates and require some customization. This becomes more important as you begin layering apps.

knewter
Engager

Thanks for your quick response I was a little confused by the documentation.

Basically I would copy over the correct TAs to the \SplunkUniversalForwarder\etc\apps folder and If I'm happy with the defaults then I'm done.

0 Karma

gfuente
Motivator

Hello

You only need to install the full app in the Splunk server. You have to install the TA on top of the universal forwarder.

Regards

0 Karma

malmoore
Splunk Employee
Splunk Employee

If you could tell me where you found the documentation confusing, that would be most helpful.

Remember also that you need to install the Splunk TA for Windows as well as the Splunk App for Active Directory helper TAs for the version of Windows Server that the domain controllers and DNS servers in your environment run.

http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/Deploymentprocess#x3._Install_a...

gfuente
Motivator

That´s it

You´ll need to restart the UF, and maybe set to enable some inputs, that may come disabled by default

Regards

0 Karma

knewter
Engager

Thanks for your quick response I was a little confused by the documentation.

Basically I would copy over the correct TAs to the \SplunkUniversalForwarder\etc\apps folder and If I'm happy with the defaults then I'm done.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...