Configure the Splunk add-on for Microsoft Active Directory on your Splunk platform
The Splunk Add-on for Microsoft Active Directory does not require any configuration edits by default. When you deploy it onto Active Directory domain controllers, it immediately begins collecting data as long as you have configured the audit policy.
Install the Splunk Add-on for Microsoft Active Directory on your distributed Splunk Enterprise deployment
Verify your data
This documentation applies to the following versions of Splunk® Enterprise: 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.3.0, 7.3.1, 7.3.2