 
					
				
		
I've already pre-installed the Splunk Enterprise in the CentOS virtual machine. The only thing left to do is to 'connect' the VM and Active Directory.
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.
You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		You would need to install a Windows Universal Forwarder on your domain controller. The install will allow you to select what you want to monitor (Windows UF only), such as System, Security, Application logs, Perfmon metrics, and I believe the newer versions will also allow you to collect admon data from AD.
You would point the Universal Forwarder at the Splunk Enterprise IP port 9997 (default). You need to listen on port 9997 by default on your Splunk Enterprise install if you haven't already set that up.
 
					
				
		
Thank you, I shall it out.
