Getting Data In

Splunk Enterprise install windows

srs_rjmd
New Member

I use the basic install on my domain controller and then install forwarder on other machines in the domain. and put my domain controller as the receiver. Will this allow me to set all logs from all system on the network.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I recommend installing Splunk on a different server than your domain controller to prevent Splunk and the DC from competing for the same resources. Install a forwarder on the DC and have all forwarders send their output to the Splunk server.
Either way, yes, you can see the logs from all systems on Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...