I have inherited a very old version of splunk - started with 6.2.5.
I upgraded it to 7.0, which broke the Windows Infrasture app. I then upgraded to 7.3.1,
and added the new verions of the Windows Infrasture app, the Active Directory App, and the windows dns app.
I am using WMi to get performance data and windows logs (I wish it was really working).
I would say it works in a "limp" mode.
I have used the splunk doc on configing the wmi, and gpo, wmi queries, user (domain) are all correct.
My Windows Overview shows a big number with host as "16" - but when I click the "16" it shows me only 3 domain hosts.