Installation

How do I configure Splunk Enterprise, installed in a CentOS VM, to monitor Windows AD-Server's (Active Directory) Event Log?

eitherlucas
Engager

I've already pre-installed the Splunk Enterprise in the CentOS virtual machine. The only thing left to do is to 'connect' the VM and Active Directory.

Tags (1)
0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.

You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.

View solution in original post

kmorris_splunk
Splunk Employee
Splunk Employee

You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.

You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.

eitherlucas
Engager

Thank you, I shall it out.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...