- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rubeniturrieta
Communicator
04-17-2015
08:25 AM
Hi everyone,
I have Splunk App for Enterprise Security, and i want to integrate it with Active Directory. I already have a dynamic lookup with assets from AD, but i want to detect security events, for example, a brute force attempt in Splunk App for Enterprise Security with Active Directory data. How can I do this?
Thanks you so much in advance
Regards
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mdessus_splunk

Splunk Employee
05-03-2015
01:48 PM
Just use an universal forwarder on your AD host, with the windows/AD specific TA. See here for more details: https://splunkbase.splunk.com/app/1680/#/overview
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mdessus_splunk

Splunk Employee
05-03-2015
01:48 PM
Just use an universal forwarder on your AD host, with the windows/AD specific TA. See here for more details: https://splunkbase.splunk.com/app/1680/#/overview
