Following the procedure:
https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Upgrade
I see that we have a separate TA for AD1.0.0 inputs, namely:
/opt/splunk/etc/deployment-apps/Splunk_TA_microsoft_ad_admon_inputs/
of which, we have a local/inputs.conf:
[admon://MYDOMAIN.ORG]
monitorSubtree = 1
baseline = 1
index = msad
disabled = false
Should this be copied to:
Splunk_TA_Windows/local/inputs.conf?
Or should we simply leave the additional TA as-is?
make sure you have only one admon inputs enabled, doesnt really matter in which TA.
Agree with @adonio. If you want to keep everything in a single place, better move it to Windows TA.
make sure you have only one admon inputs enabled, doesnt really matter in which TA.