<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk and Active Directory in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-and-Active-Directory/m-p/331066#M61328</link>
    <description>&lt;P&gt;I am currently trying to use Splunk to parse data from our Active Directory. I have currently loaded the Apps:&lt;/P&gt;

&lt;P&gt;Splunk Add-on for Microsoft Active Directory 2.1.4&lt;BR /&gt;
Splunk Supporting Add-On for Active Directory 1.0.0&lt;BR /&gt;
Splunk Add-on for Microsoft DNS 1.0.1&lt;BR /&gt;
Splunk Add-on for Windows infrastructure 1.4.1&lt;BR /&gt;
Splunk Add-on for Microsoft Windows 4.8.4&lt;/P&gt;

&lt;P&gt;What I am struggling with since there is no clear instruction set is how to get the data that is relevant to Active Directory.  I have only been able to find Splunk® App for Active Directory (Legacy) documentation. Does any one have ideas to help me get the last few steps into providing this type of data for my customer?&lt;/P&gt;

&lt;P&gt;Running:&lt;BR /&gt;
Windows Server 2012 R2&lt;BR /&gt;
16 Cores (Physical) 32 Cores (Virtual)&lt;BR /&gt;
262 GB memory&lt;BR /&gt;
Splunk 6.6.2&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jul 2017 23:39:08 GMT</pubDate>
    <dc:creator>molinarf</dc:creator>
    <dc:date>2017-07-26T23:39:08Z</dc:date>
    <item>
      <title>Splunk and Active Directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-and-Active-Directory/m-p/331066#M61328</link>
      <description>&lt;P&gt;I am currently trying to use Splunk to parse data from our Active Directory. I have currently loaded the Apps:&lt;/P&gt;

&lt;P&gt;Splunk Add-on for Microsoft Active Directory 2.1.4&lt;BR /&gt;
Splunk Supporting Add-On for Active Directory 1.0.0&lt;BR /&gt;
Splunk Add-on for Microsoft DNS 1.0.1&lt;BR /&gt;
Splunk Add-on for Windows infrastructure 1.4.1&lt;BR /&gt;
Splunk Add-on for Microsoft Windows 4.8.4&lt;/P&gt;

&lt;P&gt;What I am struggling with since there is no clear instruction set is how to get the data that is relevant to Active Directory.  I have only been able to find Splunk® App for Active Directory (Legacy) documentation. Does any one have ideas to help me get the last few steps into providing this type of data for my customer?&lt;/P&gt;

&lt;P&gt;Running:&lt;BR /&gt;
Windows Server 2012 R2&lt;BR /&gt;
16 Cores (Physical) 32 Cores (Virtual)&lt;BR /&gt;
262 GB memory&lt;BR /&gt;
Splunk 6.6.2&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 23:39:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-and-Active-Directory/m-p/331066#M61328</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2017-07-26T23:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and Active Directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-and-Active-Directory/m-p/331067#M61329</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am not really a big fan of the MS addons. I would recommend to use Universal Forwarders, if possible. That's also what Splunk recommends these days (atleast what I heard in the last meeting): try to use a UF to get your data and if you can't, try to use an addon for the task.&lt;/P&gt;

&lt;P&gt;What kind of logs are you trying to get? Event logs? There are quite a few examples in the documentation: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#WINDOWS_INPUTS:"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#WINDOWS_INPUTS:&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;

&lt;P&gt;Edit: typo&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 06:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-and-Active-Directory/m-p/331067#M61329</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2017-07-27T06:27:01Z</dc:date>
    </item>
  </channel>
</rss>

