Hi everyone,
I have Splunk App for Enterprise Security, and i want to integrate it with Active Directory. I already have a dynamic lookup with assets from AD, but i want to detect security events, for example, a brute force attempt in Splunk App for Enterprise Security with Active Directory data. How can I do this?
Thanks you so much in advance
Regards
Just use an universal forwarder on your AD host, with the windows/AD specific TA. See here for more details: https://splunkbase.splunk.com/app/1680/#/overview
Just use an universal forwarder on your AD host, with the windows/AD specific TA. See here for more details: https://splunkbase.splunk.com/app/1680/#/overview