All Apps and Add-ons

What is the frequency a universal forwarder will call the Domain Controller to resolve Active Directory Objects (evt_dc_name / evt_dns_name)?

junxianli
Explorer

Hi everyone,

It is possible to set the evt_dc_name / evt_dns_name to direct to a DC to resolve AD objects. I'll be setting the DC's fqdn into the inputs.conf for one of the universal forwarders sitting in a Windows machine.

Can I know the behavior or frequency that UF will call "ping" or "query" the DC to resolve the AD objects?

Is it safe to assume that it is by per event?

My aim is to understand and not allow the the Splunk UF instance to overload the DC with "queries".

0 Karma
1 Solution

cphair
Builder

It's not once per event, it's once per SID. One event with a lot of SIDs causes multiple lookups against the DC. Also note that the current forwarder behavior is to contact the PDC first and then revert to a local DC, so all the load will be initially directed against your PDC. This is supposed to be fixed in an upcoming version. If you don't have a compelling reason to enable SID resolution, I would turn it off.

View solution in original post

cphair
Builder

It's not once per event, it's once per SID. One event with a lot of SIDs causes multiple lookups against the DC. Also note that the current forwarder behavior is to contact the PDC first and then revert to a local DC, so all the load will be initially directed against your PDC. This is supposed to be fixed in an upcoming version. If you don't have a compelling reason to enable SID resolution, I would turn it off.

Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...