All Apps and Add-ons

[admon://] Stanza

richardphung
Communicator

Following the procedure:
https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Upgrade

I see that we have a separate TA for AD1.0.0 inputs, namely:
/opt/splunk/etc/deployment-apps/Splunk_TA_microsoft_ad_admon_inputs/

of which, we have a local/inputs.conf:

[admon://MYDOMAIN.ORG]
monitorSubtree = 1
baseline = 1
index = msad
disabled = false

Should this be copied to:
Splunk_TA_Windows/local/inputs.conf?

Or should we simply leave the additional TA as-is?

0 Karma
1 Solution

adonio
Ultra Champion

make sure you have only one admon inputs enabled, doesnt really matter in which TA.

View solution in original post

0 Karma

bhargavnariyani
Path Finder

Agree with @adonio. If you want to keep everything in a single place, better move it to Windows TA.

0 Karma

adonio
Ultra Champion

make sure you have only one admon inputs enabled, doesnt really matter in which TA.

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...