Installation

instaling configuring Auditing for Microsoft Active Directory

splunk_sa
Explorer

on Splunk 6.5.3 I have installed Splunk Add on for Microsoft Active Directory https://splunkbase.splunk.com/app/3207/
then installed universal forwarder on domain controller, I can see index=msad and others and can see AD data. I also need to collect Security logs from the domain controller. I could not see security logs unless I created a manual input form forwarder selecting Security logs from the client.
Is not the security logs from domain controller should be included by default with installation of Splunk Add on for Microsoft Active Directory? Do I need add Splunk Add on for Windows infrastructure to collect security logs from domain controllers?
The powershell remote is turned on at Domain controller and Audit logging is turned on.

Thanks
Sa

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi splunk_sa,
as described in http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Deploymentprocess you have to install on forwarder also the Splunk Add-on for Windows (https://splunkbase.splunk.com/app/742/) to ingest Windows event logs.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...