Getting Data In

Do I need Domain Account for UF when DC monitoring and Windows OS for DS?

jonwick
Path Finder

Hello Splunkers,

Do I need domain account  for UF to monitor Domain Controller ?

I suppose, I need UF on domain account when monitoring AD.

If I only wish to monitor windows standard even logs from DC then local system account is enough.

My DS would be on Linux based, do I need another new  DS on windows to push apps on DC??

In docs it has been mentioned that Splunk Enterprise should be on Windows to monitor DC, do they only mean it for indexer??? Or DS should also be  Windows based?

 

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jonwick,

you don't need a domain account to monitor a DC using Forwarder, you need only a user with privileges to read Windows EventLogs and execute scripts.

If you install Splunk UF as SYSTEM_LOCAL, you have all the needed privileges.

To be more sure, see the documentation about the app to use (I think Splunk for Windows Infrastructure) that describes the TAs to use and the needed requirements.

About the Operative System of Deployment Server and other Splunk servers, see my answer to your other question https://community.splunk.com/t5/Deployment-Architecture/Are-there-any-ideal-exceptions-where-DS-has-...

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @jonwick,

you don't need a domain account to monitor a DC using Forwarder, you need only a user with privileges to read Windows EventLogs and execute scripts.

If you install Splunk UF as SYSTEM_LOCAL, you have all the needed privileges.

To be more sure, see the documentation about the app to use (I think Splunk for Windows Infrastructure) that describes the TAs to use and the needed requirements.

About the Operative System of Deployment Server and other Splunk servers, see my answer to your other question https://community.splunk.com/t5/Deployment-Architecture/Are-there-any-ideal-exceptions-where-DS-has-...

Ciao.

Giuseppe

jonwick
Path Finder

Thanks @gcusello 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jonwick,

you're welcome!

Ciao and happy splunking.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...