All Apps and Add-ons

[admon://] Stanza

richardphung
Communicator

Following the procedure:
https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Upgrade

I see that we have a separate TA for AD1.0.0 inputs, namely:
/opt/splunk/etc/deployment-apps/Splunk_TA_microsoft_ad_admon_inputs/

of which, we have a local/inputs.conf:

[admon://MYDOMAIN.ORG]
monitorSubtree = 1
baseline = 1
index = msad
disabled = false

Should this be copied to:
Splunk_TA_Windows/local/inputs.conf?

Or should we simply leave the additional TA as-is?

0 Karma
1 Solution

adonio
Ultra Champion

make sure you have only one admon inputs enabled, doesnt really matter in which TA.

View solution in original post

0 Karma

bhargavnariyani
Path Finder

Agree with @adonio. If you want to keep everything in a single place, better move it to Windows TA.

0 Karma

adonio
Ultra Champion

make sure you have only one admon inputs enabled, doesnt really matter in which TA.

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>