- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![eitherlucas eitherlucas](https://community.splunk.com/legacyfs/online/avatars/562700.jpg)
I've already pre-installed the Splunk Enterprise in the CentOS virtual machine. The only thing left to do is to 'connect' the VM and Active Directory.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![kmorris_splunk kmorris_splunk](https://community.splunk.com/legacyfs/online/avatars/232278.jpg)
![Splunk Employee Splunk Employee](/html/@F88B7774A2BF2E9108D79A067A92A581/rank_icons/employee-16.png)
You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.
You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![kmorris_splunk kmorris_splunk](https://community.splunk.com/legacyfs/online/avatars/232278.jpg)
![Splunk Employee Splunk Employee](/html/@F88B7774A2BF2E9108D79A067A92A581/rank_icons/employee-16.png)
You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.
You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![eitherlucas eitherlucas](https://community.splunk.com/legacyfs/online/avatars/562700.jpg)
Thank you, I shall it out.
![](/skins/images/396DDBEEAC295EB5FEC41FF128E8AC0A/responsive_peak/images/icon_anonymous_message.png)