Download and configure the Splunk Add-on for Microsoft Active Directory
The Splunk Add-on for Microsoft Active Directory is available at https://apps.splunk.com/app/3207/. When you download and deploy the add-ons to domain controllers, the add-ons collect Active Directory data and send it to Splunk App for Windows Infrastructure indexers.
To users who are using TA-windows version 6.0.0 or later: TA-AD has merged with TA-windows. See Download and configure the Splunk Add-on for Windows version 6.0.0 or later.
If you're using TA-Windows version 6.0.0 or later, you don't need TA_AD and TA_DNS. TA_AD and TA_DNS are merged with TA-Windows version 6.0.0.
More information about the Active Directory add-ons
The following table lists details about the Active Directory add-on.
Add-on | Description |
---|---|
Splunk_TA_microsoft_ad | For Active Directory domain controllers that run Windows Server 2008, 2008 R2, 2012 R2 and later. |
Download the Splunk Add-on for Microsoft Active Directory
The Splunk Add-ons for Microsoft Active Directory is available on Splunkbase.
Download the add-on package and save it to an accessible place on the deployment server:
- In a web browser, proceed to the Splunk Add-on for Active Directory download page.
- Click the download link to begin the download process. You might need to sign in with your Splunk account before the download starts.
- When prompted, choose an accessible location on your deployment server to save the download. Do not attempt to run the download.
- Use an archive utility such as WinZip to unarchive the file to an accessible location.
Configure the Splunk Add-on for Microsoft Active Directory
The Splunk Add-on for Microsoft Active Directory do not require any configuration edits by default. When you deploy them onto Active Directory domain controllers, they immediately begin collecting data as long as you have configured audit policy.
Next steps
You have downloaded the Splunk Add-on for Microsoft Active Directory. The next step involves deploying those add-ons into the universal forwarders that you install on your Active Directory domain controllers.
Configure Active Directory audit policy | Deploy the Splunk Add-on for Microsoft Active Directory |
This documentation applies to the following versions of Splunk® App for Windows Infrastructure (Legacy): 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4
Feedback submitted, thanks!