Getting Data In

Active Directory Monitoring

seanp
Path Finder

I was wondering if someone could validate an answer for me. I have installed the Universal Forwarder on a domain controller and collecting data. However, there is also the Manager » Data inputs » Active Directory monitoring within Splunk. Do these collect the same data? Can I assume that using the Universal Forwarder is the preferred method to collect AD data?

Thanks!

Tags (1)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

The Active Directory monitoring process (splunk-admon.exe) can run under your full Splunk instance or on a forwarder. If you haven't read the Monitor Active Directory documentation topic, that's a good place to start.

Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...