Getting Data In

Splunk Enterprise install windows

srs_rjmd
New Member

I use the basic install on my domain controller and then install forwarder on other machines in the domain. and put my domain controller as the receiver. Will this allow me to set all logs from all system on the network.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I recommend installing Splunk on a different server than your domain controller to prevent Splunk and the DC from competing for the same resources. Install a forwarder on the DC and have all forwarders send their output to the Splunk server.
Either way, yes, you can see the logs from all systems on Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...