Trying to get data from the AD data from the forwarder to Domain Controller.
Could not see any settings within Splunk that show Active Directory and am wondering how to ingest data from that.
Hi @keldridg2 ,
I would recommend that you read some of the documentation on Splunk that explains exactly how to do this:
Getting Data In:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/WhatSplunkcanmonitor
Monitoring Active Directory:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/MonitorActiveDirectory
These documents will provide you with the information you need to monitor Active Directory.
The problem is resolved and hanks for the help.
You would put a Universal Forwarder on the Domain Controller and configure it to send the data you want (Event Logs, perfmon metrics) to your indexer(s). On windows, the Universal Forwarder installation process allows you to define those things.