Getting Data In

Active Directory Monitoring

seanp
Path Finder

I was wondering if someone could validate an answer for me. I have installed the Universal Forwarder on a domain controller and collecting data. However, there is also the Manager » Data inputs » Active Directory monitoring within Splunk. Do these collect the same data? Can I assume that using the Universal Forwarder is the preferred method to collect AD data?

Thanks!

Tags (1)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

The Active Directory monitoring process (splunk-admon.exe) can run under your full Splunk instance or on a forwarder. If you haven't read the Monitor Active Directory documentation topic, that's a good place to start.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...