Getting Data In

Can you help me configure my forwarder to send data between Domain Controller and Event Viewer?

jackmanfredi
New Member

Hello,

I have purchase Splunk Enterprise 1GB/day and I want to configure the forwarder on Domain Controller to send data about Security Events on Event Viewer. I want to index all access of domain admins.

How can I limit the indexer to send only events of access by domain admins?

Thanks

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...