No problem. I awarded you the points above since it is the correct way for Splunk On-Prem / Enterprise. As far as Splunk Cloud goes, an admin would need to go to:
Settings -> Forwarder Management -> Choose Server Classes -> Edit -> Edit Clients
A new window refreshes showing all existing clients/forwarders, and a Include (whitelist) field at the very top. Simply add in the name of the additional forward from the list and hit Save.
Thanks again
... View more
This is all in Splunk Cloud currently. So it is slightly different. However, you knocked a screw around and I was able to find the equivalent in the Cloud side of the mix.
Thanks for the help.
... View more
I have a server class called DomainControllers, and have 2 existing DCs that were added when I initially created the server class. I would like to simply add additional DCs to that server class, and I can't seem to find a quick way of doing so.
You would think it would be the same process as adding/removing when creating the server class in the beginning..
But no..
... View more
I obviously have the Active Directory Add-On installed, however when configuring the obvious questions looms, what is the best practice to get it talking to your Active Directory environment (behind firewalls, internal etc.)
Or is it easier to simply forward AD logs and create searches from those events?
Thanks
... View more