All Apps and Add-ons
Highlighted

Windows Active Directory

New Member

Hi! If I want to monitor data from a Windows Active Directory, but I'm not in the domain, how can I connect to the server and get the data?
Thanks!

0 Karma
Highlighted

Re: Windows Active Directory

SplunkTrust
SplunkTrust

If you do not have access to the domain, I am not sure how you would accomplish getting information. You will need access to the domain controllers in some fashion. You can use remote WMI calls or you can install forwarders.

There is an app for Active Directory (http://splunk-base.splunk.com/apps/Splunk+App+for+Active+Directory). The documentation on installation is very well done (http://docs.splunk.com/Documentation/ActiveDirectory). You will need access to each domain controller as you will need to put a universal forwarder on them and then you will need to add the Splunk for Active Directory app on them. Once you have the Domain Controllers forwarding to your indexer, you can enjoy the Splunk for Active Directory app. This app will show the health of your environment, the FSMO roles each server has, DNS health, GPO infomation, replication health as well as a bunch of reports about AD.

0 Karma
Highlighted

Re: Windows Active Directory

New Member

Thanks for answer.

0 Karma
Highlighted

Re: Windows Active Directory

SplunkTrust
SplunkTrust

If you feel this answered your question, please accept the answer.

0 Karma
Highlighted

Re: Windows Active Directory

Splunk Employee
Splunk Employee

You may also install the Universal Forwarder for Windows on your domain controllers, and turn on the ADMon input. There is more information here:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/AuditActiveDirectory

0 Karma