Splunk® App for Windows Infrastructure (Legacy)

Deploy and Use the Splunk App for Windows Infrastructure

Acrobat logo Download manual as PDF


On October 20, 2021, the Splunk App for Windows Infrastructure will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Windows Dashboards and Reports.
Acrobat logo Download topic as PDF

Sample searches and dashboards

This topic lists searches that you can perform to confirm that Windows data has arrived at the indexer.

If you're using TA-Windows version 6.0.0 or later, you don't need TA_AD and TA_DNS. TA_AD and TA_DNS are merged with TA-Windows version 6.0.0.

Search Active Directory data

To confirm that Active Directory data is present on the indexer, use the Search app:

  1. Log into Splunk Enterprise on the indexer, if you have not already.
  2. Load the Search app. In the system bar, select Apps > Search & Reporting. Splunk loads the Search app.
  3. Try the following searches to confirm that data is present:
  4. This search confirms that the Splunk Add-on for Microsoft Active Directory is sending data to the indexer:

    index=msad earliest=1h

    This search confirms that the Splunk Add-on for Microsoft Active Directory has been installed properly on the deployment client named <host_name>:

    index=msad host=<host_name> earliest=1h

Can't find the data?

Try the following:

  • Use Forwarder Management to confirm that the Splunk Add-on for Microsoft Active Directory has been deployed to your deployment clients.
  • Refer to the Troubleshooting manual for additional help.
Last modified on 17 October, 2019
PREVIOUS
Confirm and troubleshoot AD data collection
  NEXT
Configure Windows Domain Name Server

This documentation applies to the following versions of Splunk® App for Windows Infrastructure (Legacy): 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters