All Apps and Add-ons

Multiple Domain Controllers Best Practices (Latest Version of Splunk)

nychawk
Communicator

Greetings;

Any suggestions for a domain with multiple domain controllers? What are the pros and cons for running a UF with ad-on for Windows, and add-on for MS-AD on all vs. just my FSMO role DC? Is it best to install on all, or just my FSMO role server?

I recently changed my FSMO role server, and I am not seeing all of my data, i.e. I no longer see lockouts. (I suspect I need to flush my ADMonitoring and NearestDC.ini files, but this is only a guess).

Thank you in advance,

-mike

shogan_splunk
Splunk Employee
Splunk Employee

It is recommended to deploy the UF, and Splunk TA Windows/AD on each domain controller. Also, with atleast the Windows Security Eventlog input enabled in the Splunk TA Windows. This will ensure you index all the audit events, because some are only collected locally on the authenticating DC.

As for the admon ADMonitoring
baseline=1 Splunk TA for AD input configuration, you only need to have this on one DC per Domain.

Hope this answers your question, let me know if it doesn't.
Thanks,
Steve

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...