All Apps and Add-ons

Windows Active Directory

annaav
New Member

Hi! If I want to monitor data from a Windows Active Directory, but I'm not in the domain, how can I connect to the server and get the data?
Thanks!

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

You may also install the Universal Forwarder for Windows on your domain controllers, and turn on the ADMon input. There is more information here:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/AuditActiveDirectory

0 Karma

treinke
Builder

If you do not have access to the domain, I am not sure how you would accomplish getting information. You will need access to the domain controllers in some fashion. You can use remote WMI calls or you can install forwarders.

There is an app for Active Directory (http://splunk-base.splunk.com/apps/Splunk+App+for+Active+Directory). The documentation on installation is very well done (http://docs.splunk.com/Documentation/ActiveDirectory). You will need access to each domain controller as you will need to put a universal forwarder on them and then you will need to add the Splunk for Active Directory app on them. Once you have the Domain Controllers forwarding to your indexer, you can enjoy the Splunk for Active Directory app. This app will show the health of your environment, the FSMO roles each server has, DNS health, GPO infomation, replication health as well as a bunch of reports about AD.

There are no answer without questions
0 Karma

treinke
Builder

If you feel this answered your question, please accept the answer.

There are no answer without questions
0 Karma

annaav
New Member

Thanks for answer.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...