I've install the following on the universal forwarder running under windows 2012R2.
indexer dashboard didn't show any domain controller information.
Any ideas?
Several things to check.
SPLUNK_HOME/var/log/splunk/powershell.log
If you copied the files onto the UF, you need to unblock the ps1 script.
Did you set the execution policy to remote signed.
run the following search in the indexer and check for any powershell error.
index=msad source=Powershell sourcetype="Powershell:ScriptExecutionSummary"
If there is powershell error, try to execute them manually and see what the error is about.