All Apps and Add-ons

Multiple Domain Controllers Best Practices (Latest Version of Splunk)

nychawk
Communicator

Greetings;

Any suggestions for a domain with multiple domain controllers? What are the pros and cons for running a UF with ad-on for Windows, and add-on for MS-AD on all vs. just my FSMO role DC? Is it best to install on all, or just my FSMO role server?

I recently changed my FSMO role server, and I am not seeing all of my data, i.e. I no longer see lockouts. (I suspect I need to flush my ADMonitoring and NearestDC.ini files, but this is only a guess).

Thank you in advance,

-mike

shogan_splunk
Splunk Employee
Splunk Employee

It is recommended to deploy the UF, and Splunk TA Windows/AD on each domain controller. Also, with atleast the Windows Security Eventlog input enabled in the Splunk TA Windows. This will ensure you index all the audit events, because some are only collected locally on the authenticating DC.

As for the admon ADMonitoring
baseline=1 Splunk TA for AD input configuration, you only need to have this on one DC per Domain.

Hope this answers your question, let me know if it doesn't.
Thanks,
Steve

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...