Splunk Enterprise Security

How to integrate Splunk for Enterprise Security with Active Directory to detect security events?

rubeniturrieta
Communicator

Hi everyone,

I have Splunk App for Enterprise Security, and i want to integrate it with Active Directory. I already have a dynamic lookup with assets from AD, but i want to detect security events, for example, a brute force attempt in Splunk App for Enterprise Security with Active Directory data. How can I do this?

Thanks you so much in advance

Regards

0 Karma
1 Solution

mdessus_splunk
Splunk Employee
Splunk Employee

Just use an universal forwarder on your AD host, with the windows/AD specific TA. See here for more details: https://splunkbase.splunk.com/app/1680/#/overview

View solution in original post

mdessus_splunk
Splunk Employee
Splunk Employee

Just use an universal forwarder on your AD host, with the windows/AD specific TA. See here for more details: https://splunkbase.splunk.com/app/1680/#/overview

Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...