on Splunk 6.5.3 I have installed Splunk Add on for Microsoft Active Directory https://splunkbase.splunk.com/app/3207/
then installed universal forwarder on domain controller, I can see index=msad and others and can see AD data. I also need to collect Security logs from the domain controller. I could not see security logs unless I created a manual input form forwarder selecting Security logs from the client.
Is not the security logs from domain controller should be included by default with installation of Splunk Add on for Microsoft Active Directory? Do I need add Splunk Add on for Windows infrastructure to collect security logs from domain controllers?
The powershell remote is turned on at Domain controller and Audit logging is turned on.
Thanks
Sa
Hi splunk_sa,
as described in http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Deploymentprocess you have to install on forwarder also the Splunk Add-on for Windows (https://splunkbase.splunk.com/app/742/) to ingest Windows event logs.
Bye.
Giuseppe