You should check the splunkd.log on your AD machine to see if there are ERRORs.
Make sure that you have deployed the PowerShell (SA-ModularInput-PowerShell) and the other
prereqs that are listed in here.
Here are the etc/apps that I have deployed on my forwarder:
drwx------+ 1 SYSTEM SYSTEM 0 Jun 30 09:36 introspection_generator_addon
drwx------+ 1 SYSTEM SYSTEM 0 Jun 30 09:36 search
drwx------+ 1 SYSTEM SYSTEM 0 Jun 30 09:37 SplunkUniversalForwarder
drwx------+ 1 SYSTEM SYSTEM 0 Jun 30 09:37 learned
drwx------+ 1 Administrator None 0 Jun 30 09:50 TA-DomainController-2012R2
drwx------+ 1 Administrator None 0 Jun 30 09:50 SA-ldapsearch
drwx------+ 1 Administrator None 0 Jun 30 09:50 splunk_app_windows_infrastructure
drwx------+ 1 Administrator None 0 Jun 30 09:50 SA-ModularInput-PowerShell
drwx------+ 1 Administrator None 0 Jun 30 10:12 Splunk_TA_windows
Also, make sure that the inputs.conf files do not have "disabled = 1" for the collections that you care about.
... View more