<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why should I install Splunk on Domain Controllers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235131#M45792</link>
    <description>&lt;P&gt;Your security concerns are well-founded.  An attacker on your SDCs might go unnoticed without Splunk logging.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2017 14:57:50 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2017-01-11T14:57:50Z</dc:date>
    <item>
      <title>Why should I install Splunk on Domain Controllers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235128#M45789</link>
      <description>&lt;P&gt;Currently debating installing Splunk on all Domain Controllers.  Have a back and forth with my colleagues and security team as to if there is a real need for Splunk to be on all DC's.   Currently using Splunk 6.5.1 on 6 DC's within 2 sites out of 11 DC's within 4 sites.&lt;/P&gt;

&lt;P&gt;Debate is that it should only be installed on the PDC, however others say it should be installed on all.  Any suggestions greatly appreciated. &lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2017 21:20:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235128#M45789</guid>
      <dc:creator>medma1934</dc:creator>
      <dc:date>2017-01-10T21:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why should I install Splunk on Domain Controllers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235129#M45790</link>
      <description>&lt;P&gt;I  hope you mean you install Splunk Universal Forwarders (SUF) on your DCs rather than Splunk Core.&lt;/P&gt;

&lt;P&gt;I think the decision comes down to what behavior you want when a DC not logging to Splunk becomes primary.  When a secondary DC takes over as primary, it should would be nice to have that event logged in Splunk, which probably won't happen if not all DCs run SUF.  Also, whatever dashboards or alerts you have will continue to function uninterrupted if the new PDC is already logging to Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2017 22:27:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235129#M45790</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-01-10T22:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why should I install Splunk on Domain Controllers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235130#M45791</link>
      <description>&lt;P&gt;Thanks, Splunk agent is the only thing running on a few Domain Controllers.  Ultimately would like to put on all remaining DC but the pushback from the team is why?  The team thinks that running splunk agent on the PDC is enough.  Other than the reason of what if you move PDC to another it will log uninterrupted, i find myself having a hard time justifying why Splunk agent should be on all.&lt;/P&gt;

&lt;P&gt;As i understand, Most events are replicated across all Domain Controllers for Authentication purposes of a domain but security events as i understand dont.  I am in favor of adding Splunk agent more so because of security events in this day and age.&lt;/P&gt;

&lt;P&gt;Appreciate your info.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 14:36:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235130#M45791</guid>
      <dc:creator>medma1934</dc:creator>
      <dc:date>2017-01-11T14:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why should I install Splunk on Domain Controllers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235131#M45792</link>
      <description>&lt;P&gt;Your security concerns are well-founded.  An attacker on your SDCs might go unnoticed without Splunk logging.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 14:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235131#M45792</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-01-11T14:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why should I install Splunk on Domain Controllers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235132#M45793</link>
      <description>&lt;P&gt;Thanks.  on to battle.&lt;/P&gt;

&lt;P&gt;Appreciate the feed back.&lt;/P&gt;

&lt;P&gt;-Mike&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 16:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-should-I-install-Splunk-on-Domain-Controllers/m-p/235132#M45793</guid>
      <dc:creator>medma1934</dc:creator>
      <dc:date>2017-01-11T16:56:43Z</dc:date>
    </item>
  </channel>
</rss>

