Getting Data In

Active Directory Monitoring

seanp
Path Finder

I was wondering if someone could validate an answer for me. I have installed the Universal Forwarder on a domain controller and collecting data. However, there is also the Manager » Data inputs » Active Directory monitoring within Splunk. Do these collect the same data? Can I assume that using the Universal Forwarder is the preferred method to collect AD data?

Thanks!

Tags (1)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

The Active Directory monitoring process (splunk-admon.exe) can run under your full Splunk instance or on a forwarder. If you haven't read the Monitor Active Directory documentation topic, that's a good place to start.

Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...