All Apps and Add-ons

What is the purpose of [admon] stanza in Windows Splunk UF default folder

dokaas_2
Communicator

Our Windows admins are complaining about high CPU usage on our AD DCs and are pointing their finger at the Splunk UF. In the inputs.conf file i the default folder, there is a stanza: [admon] / interval=60 / baseline = 0. This is installed on about 10K workstations/servers. There are no other inputs.conf files with settings to monitor AD.

Does this cause the workstations to query AD even if no other inputs are defined?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The admon input monitors Active Directory and so only needs to be enabled on an AD server.  It should be disabled on workstations and non-AD servers.

See https://www.splunk.com/en_us/blog/tips-and-tricks/working-with-active-directory-on-splunk-universal-... (old, but still relevant), https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Active-Directory-ADMON/m-p/77874 , and https://docs.splunk.com/Documentation/SplunkCloud/8.1.2101/Data/MonitorActiveDirectory

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...