All Apps and Add-ons

Windows Active Directory

annaav
New Member

Hi! If I want to monitor data from a Windows Active Directory, but I'm not in the domain, how can I connect to the server and get the data?
Thanks!

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

You may also install the Universal Forwarder for Windows on your domain controllers, and turn on the ADMon input. There is more information here:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/AuditActiveDirectory

0 Karma

treinke
Builder

If you do not have access to the domain, I am not sure how you would accomplish getting information. You will need access to the domain controllers in some fashion. You can use remote WMI calls or you can install forwarders.

There is an app for Active Directory (http://splunk-base.splunk.com/apps/Splunk+App+for+Active+Directory). The documentation on installation is very well done (http://docs.splunk.com/Documentation/ActiveDirectory). You will need access to each domain controller as you will need to put a universal forwarder on them and then you will need to add the Splunk for Active Directory app on them. Once you have the Domain Controllers forwarding to your indexer, you can enjoy the Splunk for Active Directory app. This app will show the health of your environment, the FSMO roles each server has, DNS health, GPO infomation, replication health as well as a bunch of reports about AD.

There are no answer without questions
0 Karma

treinke
Builder

If you feel this answered your question, please accept the answer.

There are no answer without questions
0 Karma

annaav
New Member

Thanks for answer.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...