I'm currently in the process of evaluating Splunk for active directory monitoring. What I'm interested in, is using it to monitor several domains using universal forwarders. What I've done so far is to set up a Splunk server using the local system account, and then I've set up universal forwarders in two domains using domain accounts and enabling active directory monitoring during the setup.
Unfortunately this isn't working for me, as initially I got some data from the AD monitor running in the same domain as the Splunk server, but that only lasted for about an hour.
Is what I'm attempting to do possible, and if so, what am I doing wrong?
... View more