Looking to see if I can configure Splunk to use 1 AD account where that account (that domain) has AD trusts with other domains I need to pull information from? If I can does it matter if the account is in a child domain querying the parent domain? Or do I need a account in each domain and or forest?
You will need a trust relationship, that may or may not already be set up. To check you can attempt to logon to a system in the parent domain with the credentials from the child domain. If you're successful, then you're all set.
Example. Parent domain is DomainA and Child domain is DomainC. Attempt to logon to a system in DomainA with the following credential format: DomainC\username
.