All Apps and Add-ons

Windows Active Directory

annaav
New Member

Hi! If I want to monitor data from a Windows Active Directory, but I'm not in the domain, how can I connect to the server and get the data?
Thanks!

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

You may also install the Universal Forwarder for Windows on your domain controllers, and turn on the ADMon input. There is more information here:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/AuditActiveDirectory

0 Karma

treinke
Builder

If you do not have access to the domain, I am not sure how you would accomplish getting information. You will need access to the domain controllers in some fashion. You can use remote WMI calls or you can install forwarders.

There is an app for Active Directory (http://splunk-base.splunk.com/apps/Splunk+App+for+Active+Directory). The documentation on installation is very well done (http://docs.splunk.com/Documentation/ActiveDirectory). You will need access to each domain controller as you will need to put a universal forwarder on them and then you will need to add the Splunk for Active Directory app on them. Once you have the Domain Controllers forwarding to your indexer, you can enjoy the Splunk for Active Directory app. This app will show the health of your environment, the FSMO roles each server has, DNS health, GPO infomation, replication health as well as a bunch of reports about AD.

There are no answer without questions
0 Karma

treinke
Builder

If you feel this answered your question, please accept the answer.

There are no answer without questions
0 Karma

annaav
New Member

Thanks for answer.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...