Installation

instaling configuring Auditing for Microsoft Active Directory

splunk_sa
Explorer

on Splunk 6.5.3 I have installed Splunk Add on for Microsoft Active Directory https://splunkbase.splunk.com/app/3207/
then installed universal forwarder on domain controller, I can see index=msad and others and can see AD data. I also need to collect Security logs from the domain controller. I could not see security logs unless I created a manual input form forwarder selecting Security logs from the client.
Is not the security logs from domain controller should be included by default with installation of Splunk Add on for Microsoft Active Directory? Do I need add Splunk Add on for Windows infrastructure to collect security logs from domain controllers?
The powershell remote is turned on at Domain controller and Audit logging is turned on.

Thanks
Sa

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi splunk_sa,
as described in http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Deploymentprocess you have to install on forwarder also the Splunk Add-on for Windows (https://splunkbase.splunk.com/app/742/) to ingest Windows event logs.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...