All Apps and Add-ons

Splunk app for Active Directory

L3on1d
Explorer

Hello!

"Enable auditing and local PowerShell script execution on Active Directory servers"

Which scripts app runs on AD DC? How app will affect on the performance? Thanks.

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

Typically, the TA for DNSServer and DomainController (in the Addons directory inside the Splunk for AD app folder $SPLUNK_HOME\etc\apps\Splunk_for_ActiveDirectory\appserver\addons\, will run the necessary PowerShell scripts for the inputs for each DNS and domain controller. The cpu may reach a few percent more when the PowerShell scripts are running due to the WMI calls they make, but you shouldn't notice much of a performance hit once the initial apps are deployed.
-Jeff.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...