Installation

instaling configuring Auditing for Microsoft Active Directory

splunk_sa
Explorer

on Splunk 6.5.3 I have installed Splunk Add on for Microsoft Active Directory https://splunkbase.splunk.com/app/3207/
then installed universal forwarder on domain controller, I can see index=msad and others and can see AD data. I also need to collect Security logs from the domain controller. I could not see security logs unless I created a manual input form forwarder selecting Security logs from the client.
Is not the security logs from domain controller should be included by default with installation of Splunk Add on for Microsoft Active Directory? Do I need add Splunk Add on for Windows infrastructure to collect security logs from domain controllers?
The powershell remote is turned on at Domain controller and Audit logging is turned on.

Thanks
Sa

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi splunk_sa,
as described in http://docs.splunk.com/Documentation/ActiveDirectory/1.2.2/DeployAD/Deploymentprocess you have to install on forwarder also the Splunk Add-on for Windows (https://splunkbase.splunk.com/app/742/) to ingest Windows event logs.
Bye.
Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...