Splunk Enterprise Security

Does Splunk_TA_microsoft_dns need to be deployed to every domain controller?



I am looking at Splunk_TA_microsoft_dns. We deployed it to every domain controller, but I was wondering if we really needed to do that. For things like the dns-zoneinfo.ps1 script, it seems we really only need this once per DNS server, not from every domain controller ever.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!