Installation

instaling configuring Auditing for Microsoft Active Directory

splunk_sa
Explorer

on Splunk 6.5.3 I have installed Splunk Add on for Microsoft Active Directory https://splunkbase.splunk.com/app/3207/
then installed universal forwarder on domain controller, I can see index=msad and others and can see AD data. I also need to collect Security logs from the domain controller. I could not see security logs unless I created a manual input form forwarder selecting Security logs from the client.
Is not the security logs from domain controller should be included by default with installation of Splunk Add on for Microsoft Active Directory? Do I need add Splunk Add on for Windows infrastructure to collect security logs from domain controllers?
The powershell remote is turned on at Domain controller and Audit logging is turned on.

Thanks
Sa

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi splunk_sa,
as described in http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Deploymentprocess you have to install on forwarder also the Splunk Add-on for Windows (https://splunkbase.splunk.com/app/742/) to ingest Windows event logs.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...