Monitoring Splunk

Monitoring Active Directory using Splunk Enterprise Single instance on LINUX ?

neerajshah81
Path Finder

Hello All, We have a single instance Splunk enterprise (version 7.1) deployment on Linux which is doing everything . We would like to monitor our AD using SPLUNK. I am confused by reading http://docs.splunk.com/Documentation/Splunk/7.1.1/Data/MonitorActiveDirectory , does it mean that for this to work Splunk instance needs to installed be on Windows ? How do customers which have Splunk installed on Linux monitor AD then ?

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

i think that the easiest way will be to install a forwarder on the AD server, have the TA windows installed on the forwarder and enable the [admon] input
read more here:
https://splunkbase.splunk.com/app/742/#/details
http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Configuration
i guess in the documents, you can refer to a Universal Forwarder as well
you will also need the windows TA on your Splunk indexer (linux machine)

hope it helps

View solution in original post

0 Karma

neerajshah81
Path Finder

Adonio, one more question. I was referring to your other posts on this forum in helping users with the same concerns. What is the difference between ( https://splunkbase.splunk.com/app/742/#/details ) and ( https://splunkbase.splunk.com/app/1680/) and which of the two one would you recommend for monitoring AD ?

Thanks in advance

0 Karma

adonio
Ultra Champion

the first one is a TA and the second one is an app with views and dashboards etc.
will recommend to read here about different kind of apps:
https://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Whatsanapp

0 Karma

adonio
Ultra Champion

i think that the easiest way will be to install a forwarder on the AD server, have the TA windows installed on the forwarder and enable the [admon] input
read more here:
https://splunkbase.splunk.com/app/742/#/details
http://docs.splunk.com/Documentation/WindowsAddOn/5.0.0/User/Configuration
i guess in the documents, you can refer to a Universal Forwarder as well
you will also need the windows TA on your Splunk indexer (linux machine)

hope it helps

0 Karma

neerajshah81
Path Finder

Hi Adonio, thanks for responding. I checked those links and it seems like we can get basic stats such as performance counters from CPU, Memory , registry monitoring etc on whichever Windows system we configure the forwarder on.

Typically from Active Dir monitoring point of view, one would be more interested in watching for changes such user addition / deletion, group addition/deletion/modification , group policy changes..and so on. Do you have any references to point me to how to configure the TA Windows & [admon] input to log these type of changes ?

Appreciate your help.

0 Karma

adonio
Ultra Champion

the adding and deleting users as well as other relevant events are being collected by the security event logs.
you will want to enable that input on your AD/DC forwarder

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...