I looked at the Using LDAP in Splunk Manual. How can I use AD instead of LDAP?
For practical purposes, AD is LDAP. (Albeit, with Microsoft's TOTALLY WONDERFUL nonstandard extensions ... embrace, extend, ... extinguish?) You can connect Splunk to your AD servers just fine -- however, for simplicity, I would recommend using an AD Global Catalog server/port.