Monitoring Splunk

Monitoring Active Directory using Splunk Enterprise Single instance on LINUX ?

neerajshah81
Path Finder

Hello All, We have a single instance Splunk enterprise (version 7.1) deployment on Linux which is doing everything . We would like to monitor our AD using SPLUNK. I am confused by reading http://docs.splunk.com/Documentation/Splunk/7.1.1/Data/MonitorActiveDirectory , does it mean that for this to work Splunk instance needs to installed be on Windows ? How do customers which have Splunk installed on Linux monitor AD then ?

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

i think that the easiest way will be to install a forwarder on the AD server, have the TA windows installed on the forwarder and enable the [admon] input
read more here:
https://splunkbase.splunk.com/app/742/#/details
http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Configuration
i guess in the documents, you can refer to a Universal Forwarder as well
you will also need the windows TA on your Splunk indexer (linux machine)

hope it helps

View solution in original post

0 Karma

neerajshah81
Path Finder

Adonio, one more question. I was referring to your other posts on this forum in helping users with the same concerns. What is the difference between ( https://splunkbase.splunk.com/app/742/#/details ) and ( https://splunkbase.splunk.com/app/1680/) and which of the two one would you recommend for monitoring AD ?

Thanks in advance

0 Karma

adonio
Ultra Champion

the first one is a TA and the second one is an app with views and dashboards etc.
will recommend to read here about different kind of apps:
https://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Whatsanapp

0 Karma

adonio
Ultra Champion

i think that the easiest way will be to install a forwarder on the AD server, have the TA windows installed on the forwarder and enable the [admon] input
read more here:
https://splunkbase.splunk.com/app/742/#/details
http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Configuration
i guess in the documents, you can refer to a Universal Forwarder as well
you will also need the windows TA on your Splunk indexer (linux machine)

hope it helps

0 Karma

neerajshah81
Path Finder

Hi Adonio, thanks for responding. I checked those links and it seems like we can get basic stats such as performance counters from CPU, Memory , registry monitoring etc on whichever Windows system we configure the forwarder on.

Typically from Active Dir monitoring point of view, one would be more interested in watching for changes such user addition / deletion, group addition/deletion/modification , group policy changes..and so on. Do you have any references to point me to how to configure the TA Windows & [admon] input to log these type of changes ?

Appreciate your help.

0 Karma

adonio
Ultra Champion

the adding and deleting users as well as other relevant events are being collected by the security event logs.
you will want to enable that input on your AD/DC forwarder

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...