Monitoring Splunk

Splunk AD logs

revanthammineni
Path Finder

Hello Dear Splunkers,

Hope you're doing good! My organization has over 20k servers including Windows and Linux. We have so much of data coming in everyday. We are currently trying to build some usecases for the Windows AD logs. Any apps that you guys can recommend for a distributed environment which I can leverage for the AD logs? 

Also, We have Splunk ES and we are trying to use it's capabilities with our overall logs. Please provide some recommendations.

Thanks in Advance.

Tags (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

For AD, try the Splunk Add-on for Infrastructure.

You'll have to be more specific about your ES desires.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...