As the question above states;
Since the 6.2.1 update of Splunk, our active directory inputs are no longer gathering 'admonEventType=Sync' events.
Sync events are the main meat of the AD indexes, containing the actual listing for objects.
Our last _time entry is 12/16/2014 around 10am, immediately after the 6.2.1 update.
The other 3 admonEventTypes are still collected. Start, Scheme, update.
I have recreated the inputs on 2 servers in different location, and the same behavior remains. Only 3 of the event types are being collected.