I definitely (now) have the Add-ons in the right path and see them below forwarder management.  They are "deployed" to the Windows servers where I should be getting data from yet I am still getting the errors related to Search "sourcetype="ActiveDirectory*" | head 5" and same for sourcetype="MSAD*" | head 5 
 That is the same on both of the Splunk servers I'm working with (the Add-ons for Windows 2008 domain are in place, and yet we're not getting those events capture for the Windows Infrastructure App. 
 Next suggestion? 
 (And stupid question follow-up... The add-ons were originally kept below the Windows Infrastructure App.  I copied them up and into the Deployment-Apps area, as I also did with the Infrastructure App.  Should I not have the Infrastructure App there as an App for deployment?  Should I have had just the Add-ons?  Why don't the add-ons go along for the ride when the Infrastructure App is being deployed??) 
						
					
					... View more