Installation

How do I configure Splunk Enterprise, installed in a CentOS VM, to monitor Windows AD-Server's (Active Directory) Event Log?

eitherlucas
Engager

I've already pre-installed the Splunk Enterprise in the CentOS virtual machine. The only thing left to do is to 'connect' the VM and Active Directory.

Tags (1)
0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.

You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.

View solution in original post

kmorris_splunk
Splunk Employee
Splunk Employee

You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.

You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.

eitherlucas
Engager

Thank you, I shall it out.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...