All Apps and Add-ons

Multiple Domain Controllers Best Practices (Latest Version of Splunk)

nychawk
Communicator

Greetings;

Any suggestions for a domain with multiple domain controllers? What are the pros and cons for running a UF with ad-on for Windows, and add-on for MS-AD on all vs. just my FSMO role DC? Is it best to install on all, or just my FSMO role server?

I recently changed my FSMO role server, and I am not seeing all of my data, i.e. I no longer see lockouts. (I suspect I need to flush my ADMonitoring and NearestDC.ini files, but this is only a guess).

Thank you in advance,

-mike

shogan_splunk
Splunk Employee
Splunk Employee

It is recommended to deploy the UF, and Splunk TA Windows/AD on each domain controller. Also, with atleast the Windows Security Eventlog input enabled in the Splunk TA Windows. This will ensure you index all the audit events, because some are only collected locally on the authenticating DC.

As for the admon ADMonitoring
baseline=1 Splunk TA for AD input configuration, you only need to have this on one DC per Domain.

Hope this answers your question, let me know if it doesn't.
Thanks,
Steve

Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...