If my enterprise AD admins will not allow Splunk Agent on DCs, is DNS Debug logging and Windows Event Forwarding my only option? Do you have any reference/suggestions regarding this configuration? Additionally, and read on the article, it seems Stream is the preferred implementation and not DNS Debug. Can you elaborate as to why? Thank you much in advance.
... View more