<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get Windows domain log in data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128813#M26441</link>
    <description>&lt;P&gt;You don't need the active directory app to monitor user authentication by the domain controllers, but you do need the windows security log on the domain controllers.  WMI can work, but WMI is not as reliable as ChrisG mentioned. &lt;BR /&gt;
Also, monitoring only domain controllers will not show you local account logon events.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2014 00:39:30 GMT</pubDate>
    <dc:creator>lukejadamec</dc:creator>
    <dc:date>2014-01-29T00:39:30Z</dc:date>
    <item>
      <title>How to get Windows domain log in data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128811#M26439</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am trying to collect data for Windows log on/off time, user and machine. I am running Splunk enterprise 6 on a linux. Is there any "easy" way to get this data to splunk without using forwarders or splunk app for active directory?&lt;/P&gt;

&lt;P&gt;Thanks. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2014 23:18:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128811#M26439</guid>
      <dc:creator>Bill_B</dc:creator>
      <dc:date>2014-01-28T23:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Windows domain log in data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128812#M26440</link>
      <description>&lt;P&gt;You can monitor a variety of Windows data without a forwarder, but there are tradeoffs to using WMI. Have you looked at the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/ConsiderationsfordecidinghowtomonitorWindowsdata"&gt;Windows data information&lt;/A&gt; in the Getting Data In manual? It has information about WMI and ActiveDirectory, as well as event logs, registry, host, and performance data.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 00:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128812#M26440</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2014-01-29T00:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Windows domain log in data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128813#M26441</link>
      <description>&lt;P&gt;You don't need the active directory app to monitor user authentication by the domain controllers, but you do need the windows security log on the domain controllers.  WMI can work, but WMI is not as reliable as ChrisG mentioned. &lt;BR /&gt;
Also, monitoring only domain controllers will not show you local account logon events.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 00:39:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128813#M26441</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-01-29T00:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Windows domain log in data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128814#M26442</link>
      <description>&lt;P&gt;Thanks for the response! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 02:30:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128814#M26442</guid>
      <dc:creator>Bill_B</dc:creator>
      <dc:date>2014-01-30T02:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Windows domain log in data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128815#M26443</link>
      <description>&lt;P&gt;Yer welcome, but be warned.  Trying to monitor logon logoff transactions with Anything is fraught with peril because Windows often times loses the logoff part.  Perhaps with the 6.1 Splunk you can create a knowledge object that associates a system shutdown with a logoff, but I've not tried it.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 03:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Windows-domain-log-in-data/m-p/128815#M26443</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-01-30T03:00:17Z</dc:date>
    </item>
  </channel>
</rss>

