Documentation does not mention user permissions. I'd rather not give this service account full permissions if I can help it.
*Side question: does anyone have any experience with Windows Server 2016 for AD DS? Will this app work with it?
You'll need to give the Service Account access to read the information you want Splunk to be able to collect/access. It only needs read rights.
2016 server is still unsupported at the moment, but support is coming soon for the UF. The apps themselves are on different release schedules, so I suggest holding off on that unless you want to beta test in that environment. I have a 2016 server with 2 DCs that I plan on loading it to...just haven't gotten to it yet.
You'll need to give the Service Account access to read the information you want Splunk to be able to collect/access. It only needs read rights.
2016 server is still unsupported at the moment, but support is coming soon for the UF. The apps themselves are on different release schedules, so I suggest holding off on that unless you want to beta test in that environment. I have a 2016 server with 2 DCs that I plan on loading it to...just haven't gotten to it yet.