Content Pack for Windows Dashboards and Reports

Content Pack for Windows Dashboards and Reports

This documentation does not apply to the most recent version of Content Pack for Windows Dashboards and Reports. For documentation on the most recent version, go to the latest release.

About the Content Pack for Windows Dashboards and Reports

The Content Pack for Windows Dashboards and Reports gives you visibility into the health and performance of your Microsoft Windows Server and Active Directory environments.

You can use the Content Pack for Windows Dashboards and Reports to perform the following tasks:

  • Identify infrastructure problems, such as non-running services and load issues.
  • Monitor the performance of all servers throughout your Windows environment.
  • Monitor security events, such as virus outbreaks and anomalous logons.
  • Track administrative changes to the environment.
  • Plan for capacity expansion.

The content pack includes the following components:

  • Active Directory Entity Type with vital metrics that describe the overall performance of entities for Domain Controllers.
  • One entity discovery search that you can enable when you are ready to import your Windows AD entities. See Enable entity discovery search.
  • Dashboards and reports for proactive environment management.
  • Knowledge objects that populate the dashboards and reports present in the content pack.

The content pack components let you monitor system, server, network, and printer availability. You can also leverage additional modules to monitor other aspects of your Windows network:

  • Use Splunk Add-on for Microsoft Windows to monitor your Microsoft Windows Server.
  • Use the Splunk Supporting Add-on for Microsoft Windows Active Directory to monitor your Microsoft Windows Server Active Directory.


You can install the Windows Dashboards and Reports Content Pack after installing the Splunk App for Content Packs on the search head where you have installed ITSI or ITE Work.

For installation instructions, see Install and configure the Splunk App for Content Packs in the Splunk App for Content Packs manual.

Deployment requirements

Use the following table to ensure you are running the correct version of the content pack, ITSI/IT Essentials Work, Splunk Add-on for Microsoft Windows and Splunk Supporting Add-on for Active Directory:

Splunk App for Content Packs version Content pack version ITSI version IT Essentials Work version Splunk Add-on for Microsoft Windows version Splunk Supporting Add-on for Active Directory version
1.9.0 1.2.0 4.15.x, 4.16.x 4.15.x, 4.16.x 8.6.0 3.0.6
1.6.0 1.1.0 4.11.4 and higher 4.11.4 and higher 8.0.0, 8.4.0, 8.5.0 3.0.3, 3.0.4
1.5.0 1.0.1 4.9.6 and higher, 4.11.3 and higher 4.9.6 and higher, 4.11.3 and higher 7.0.0, 8.0.0 3.0.2, 3.0.3
1.3.0 1.0.0 4.9.0 or higher 4.9.0 or higher 7.0.0, 8.0.0, 8.1.2 3.0.2, 3.0.3

Configuration requirements

Use the following table to review the configuration requirements for the Content Pack for Windows Dashboards and Reports:

Component Search head Indexer Forwarder
Content Pack for Windows Dashboards and Reports X
Splunk Add-on for Microsoft Windows X X X
Splunk Supporting Add-on for Active Directory X

Additional resources

Last modified on 21 April, 2023
  Release Notes for the Content Pack for Windows Dashboards and Reports

This documentation applies to the following versions of Content Pack for Windows Dashboards and Reports: 1.2.0

Was this topic useful?

You must be logged into in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters