Installation

How do I configure Splunk Enterprise, installed in a CentOS VM, to monitor Windows AD-Server's (Active Directory) Event Log?

eitherlucas
Engager

I've already pre-installed the Splunk Enterprise in the CentOS virtual machine. The only thing left to do is to 'connect' the VM and Active Directory.

Tags (1)
0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.

You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.

View solution in original post

kmorris_splunk
Splunk Employee
Splunk Employee

You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.

You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.

eitherlucas
Engager

Thank you, I shall it out.

0 Karma
Get Updates on the Splunk Community!

Best Strategies to Optimize Observability Costs

 Join us on Tuesday, May 6, 2025, at 11 AM PDT / 2 PM EDT for an insightful session on optimizing ...

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...