All Apps and Add-ons

Multiple Domain Controllers Best Practices (Latest Version of Splunk)



Any suggestions for a domain with multiple domain controllers? What are the pros and cons for running a UF with ad-on for Windows, and add-on for MS-AD on all vs. just my FSMO role DC? Is it best to install on all, or just my FSMO role server?

I recently changed my FSMO role server, and I am not seeing all of my data, i.e. I no longer see lockouts. (I suspect I need to flush my ADMonitoring and NearestDC.ini files, but this is only a guess).

Thank you in advance,


Splunk Employee
Splunk Employee

It is recommended to deploy the UF, and Splunk TA Windows/AD on each domain controller. Also, with atleast the Windows Security Eventlog input enabled in the Splunk TA Windows. This will ensure you index all the audit events, because some are only collected locally on the authenticating DC.

As for the admon ADMonitoring
baseline=1 Splunk TA for AD input configuration, you only need to have this on one DC per Domain.

Hope this answers your question, let me know if it doesn't.

Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.