Splunk Enterprise Security

Does Splunk_TA_microsoft_dns need to be deployed to every domain controller?



I am looking at SplunkTAmicrosoft_dns. We deployed it to every domain controller, but I was wondering if we really needed to do that. For things like the dns-zoneinfo.ps1 script, it seems we really only need this once per DNS server, not from every domain controller ever.

0 Karma