All Apps and Add-ons

[admon://] Stanza

richardphung
Communicator

Following the procedure:
https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Upgrade

I see that we have a separate TA for AD1.0.0 inputs, namely:
/opt/splunk/etc/deployment-apps/Splunk_TA_microsoft_ad_admon_inputs/

of which, we have a local/inputs.conf:

[admon://MYDOMAIN.ORG]
monitorSubtree = 1
baseline = 1
index = msad
disabled = false

Should this be copied to:
Splunk_TA_Windows/local/inputs.conf?

Or should we simply leave the additional TA as-is?

0 Karma
1 Solution

adonio
Ultra Champion

make sure you have only one admon inputs enabled, doesnt really matter in which TA.

View solution in original post

0 Karma

bhargavnariyani
Path Finder

Agree with @adonio. If you want to keep everything in a single place, better move it to Windows TA.

0 Karma

adonio
Ultra Champion

make sure you have only one admon inputs enabled, doesnt really matter in which TA.

0 Karma
Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...