Hello,
We are testing splunk light on a linux Ubuntu 14.04 machine. I was curious if you can monitor Active Directory with Splunk light or is that an enterprise feature?
Thanks
Yes you can monitor AD with SL. The Windows add-on can help with that.
Thanks for the response but i looked at the documentation for the add-on and it looks like it will only monitor certain information, nothing about AD.
http://docs.splunk.com/Documentation/WindowsAddOn/latest/User/AbouttheSplunkAdd-onforWindows
I also found this document on how to configure it from the command line but our version of splunk doesn't have a admon.conf file.
http://docs.splunk.com/Documentation/Splunk/5.0/Data/AuditActiveDirectory