SlideShare a Scribd company logo
1 of 2
Download to read offline
Computer Account
Information
Site
Information
User Password and
Account Information
Organizational Unit
Information
Compliance
Information
Domain
Information
Domain
Controllers
DNS Server
Active Directory
With the Splunk App for Active Directory you can:
•	Monitor Active Directory Forest for potential security
breaches and non-compliant usage patterns
•	Audit changes to group policies, user, group and computer
objects in real time
•	View detailed topology statistics on all the objects of your
Active Directory top down from the Forest to individual
user and computer accounts
•	Monitor the operational health of Active Directory across
site and domain boundaries
Microsoft Windows Server Active Directory is the foundation of
an IT infrastructure. It is the central location for user configuration
information, authentication requests and information about all
the computers that run your business. When issues occur in Active
Directory, the effect is evident and widespread—users are unable to
login, access privileges expire, e-mail stops flowing and websites
hang, Organizations need a proactive, easy-to-deploy solution that
will uncover the data needed to diagnose the issue, fix its root
cause and restore service.
Splunk App for Active Directory
The Splunk App for Active Directory was designed to tackle the
challenges faced by IT organizations—avoiding service outages,
as well as proactive management and compliance reporting of
the Active Directory infrastructure—from one place. This allows
administrators to avoid the problems of traditional tools that just
deliver health statistics, but miss reporting crucial compliance and
auditing information. By monitoring the health and performance
of an Active Directory Forest—from the forest, domains and
sites that comprise the structure to the individual objects that
represent tangible assets and then adding on compliance and
auditing information—administrators can gain real-time operational
intelligence about the entire Active Directory infrastructure.
Armed with this deep insight from the data that is captured from
Security, System and Audit logs, performance monitors and
active service monitoring, your Active Directory Administrator
can quickly pinpoint problems, identify security breaches and
ensure corporate compliance goals.
Real-time Monitoring and Auditing for Microsoft
Windows Server Active Directory
Splunk® App for Active Directory
F A C T S H E E T
Active Directory Data Inputs
Active Directory Forest Topology Report
•	 Real-time operational health and performance
data of the Windows Server Active Directory
Infrastructure
•	 Integrated auditing features that track activity from
root domains to the individual objects in a site
•	 Extensive change management reports that deliver
views to changes in objects and policies templates,
increasing uptime
H I G H L I G H T S
www.splunk.com
250 Brannan St, San Francisco, CA, 94107 info@splunk.com | sales@splunk.com 866-438-7758 | 415-848-8400 www.splunkbase.com
Copyright © 2012 Splunk Inc. All rights reserved. Splunk Enterprise is protected by U.S. and international copyright and intellectual property laws.
Splunk is a registered trademark or trademark of Splunk Inc. in the United States and/or other jurisdictions. All other marks and names mentioned
herein may be trademarks of their respective companies. Item # FS-Splunk-AppActiveDirectory-102
Product Requirements
Supported Windows Server Versions
The Splunk App for Active Directory supports Active Directory
Forests running on Windows Server 2003 R2, Windows Server
2008, Windows Server 2008 R2 and Windows Server 2012.
Splunk Requirements
All instances of Splunk in a Splunk App for Active Directory requires
Splunk Enterprise v4.3.2 or later and Sideview Utils v1.2.5 or later.
All universal forwarders in a Splunk App for Active Directory
deployment must run Splunk Enterprise v4.2.5 or later.
F A C T S H E E T
www.splunk.com
250 Brannan St, San Francisco, CA, 94107 info@splunk.com | sales@splunk.com 866-438-7758 | 415-848-8400 www.splunkbase.com
Try Out the App, it’s Free!
Go to www.splunk.com/microsoft to learn more.
Splunk App for Active Directory Features
The Splunk App for Active Directory provides several specialized
features to monitor Active Directory, including:
Topology Reports – Displays a complete view of the entire Active
Directory Forest and the underlying Domains, Sites and Domain
Controllers that are being monitored. This allows an Active Directory
administrator to view the entire Forest from one single view
rather then opening multiple consoles for information.
Domain Services – Displays information on the Domains, Sites and
Domain controllers that belong to the Active Directory Forest.
The information here delivers real-time statistics as to how the
individual components are operating and how they are working
together. Information gathered here is used to troubleshoot login
issues, account for missing object information due to replication
failures, and monitor performance of the directory service and
domain controller load.
DNS Services – Displays information about the health, configuration,
and performance of the DNS servers and DNS zones that host the
Active Directory domains. Due to the dependency that Active
Directory has on DNS, any changes made to DNS servers,
performance issues or outages can create service disruptions
on the Active Directory side. The information here allows Active
Directory Administrators to view information about the DNS
infrastructure that is usually administered by the networking
team to see if issues in DNS are impacting the Active Directory
Forest, producing faster resolution times.
User Logon Failures – Displays failed attempts by users to log onto
a specific domain in the Active Directory Forest. Information here
is used to protect the Active Forest from malicious unauthorized
login activities. From one console, administrators can then view
the multiple ways a security breach may be attempted across
the entire Forest.
Anomalous Logons – Displays information on uncharacteristic
usage patterns, such as a user logging in from multiple workstations.
The information gathered here can be used to monitor for attempted
security breaches across the Forest.
User Utilization – Displays the user and workstation load managed
by Active Directory Forest. Information here is used for monitoring
the load Domain Controllers are carrying and can then be used
to justify hardware and software acquisitions.
Change Management – Displays changes made to objects in
the Active Directory Forest. Helpdesk and admin staff can
track changes made to computer accounts, domain accounts,
organizational units and group policy objects to decrease
support calls and pinpoint user issues.
Free Download
Download Splunk. You’ll get a Splunk Enterprise license for 60
days and you can index up to 500 megabytes of data per day.
You can convert to a perpetual Free license or purchase an
Enterprise license by contacting sales@splunk.com.

More Related Content

Viewers also liked

Viewers also liked (12)

Unit plan Assure 5
Unit plan Assure 5Unit plan Assure 5
Unit plan Assure 5
 
sharing folder
sharing folder sharing folder
sharing folder
 
Modos de produccion
Modos de produccionModos de produccion
Modos de produccion
 
Alianzas tecnologicas 3 ra parte. FRANKLIN ANGULO RANGEL.
Alianzas tecnologicas 3 ra parte. FRANKLIN ANGULO RANGEL.Alianzas tecnologicas 3 ra parte. FRANKLIN ANGULO RANGEL.
Alianzas tecnologicas 3 ra parte. FRANKLIN ANGULO RANGEL.
 
Torres acacia apresentação
Torres acacia   apresentaçãoTorres acacia   apresentação
Torres acacia apresentação
 
Bảng dính chữ xốp ,bộ chữ xốp mủ cao xu,khung dính chữ sốp trang trí hội nghị...
Bảng dính chữ xốp ,bộ chữ xốp mủ cao xu,khung dính chữ sốp trang trí hội nghị...Bảng dính chữ xốp ,bộ chữ xốp mủ cao xu,khung dính chữ sốp trang trí hội nghị...
Bảng dính chữ xốp ,bộ chữ xốp mủ cao xu,khung dính chữ sốp trang trí hội nghị...
 
2009藝文中心成果
2009藝文中心成果2009藝文中心成果
2009藝文中心成果
 
Neural Pulsars: Kevin Haywood
Neural Pulsars: Kevin HaywoodNeural Pulsars: Kevin Haywood
Neural Pulsars: Kevin Haywood
 
Cupp education theory paper
Cupp   education theory paperCupp   education theory paper
Cupp education theory paper
 
tiểu luận wincc
tiểu luận wincctiểu luận wincc
tiểu luận wincc
 
Calidad de software
Calidad de softwareCalidad de software
Calidad de software
 
Interview questions answers internships
Interview questions answers internshipsInterview questions answers internships
Interview questions answers internships
 

Similar to Splunk for active_directory

Splunk for xen_desktop
Splunk for xen_desktopSplunk for xen_desktop
Splunk for xen_desktopGreg Hanchin
 
Splunk Enterprise 6.1 Solutions Brief
Splunk Enterprise 6.1 Solutions BriefSplunk Enterprise 6.1 Solutions Brief
Splunk Enterprise 6.1 Solutions BriefManish Kalra
 
Office 365 Dashboards - Analytical Reporting Tools
Office 365 Dashboards - Analytical Reporting ToolsOffice 365 Dashboards - Analytical Reporting Tools
Office 365 Dashboards - Analytical Reporting ToolsUnifyCloud
 
Splunk for application_management
Splunk for application_managementSplunk for application_management
Splunk for application_managementGreg Hanchin
 
Splunk sales presentation
Splunk sales presentationSplunk sales presentation
Splunk sales presentationjpelletier123
 
Splunk app for_windows
Splunk app for_windowsSplunk app for_windows
Splunk app for_windowsGreg Hanchin
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...SolarWinds
 
Splunk for exchange
Splunk for exchangeSplunk for exchange
Splunk for exchangeGreg Hanchin
 
Splunk for exchange
Splunk for exchangeSplunk for exchange
Splunk for exchangeGreg Hanchin
 
IRJET- Research Paper on Active Directory
IRJET-  	  Research Paper on Active DirectoryIRJET-  	  Research Paper on Active Directory
IRJET- Research Paper on Active DirectoryIRJET Journal
 
Getting Started with Splunk
Getting Started with SplunkGetting Started with Splunk
Getting Started with SplunkSplunk
 
FOISDBA-Ver1.1.pptx
FOISDBA-Ver1.1.pptxFOISDBA-Ver1.1.pptx
FOISDBA-Ver1.1.pptxssuser20fcbe
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionSplunk
 
SplunkLive! Customer Presentation - Staples
SplunkLive! Customer Presentation - StaplesSplunkLive! Customer Presentation - Staples
SplunkLive! Customer Presentation - StaplesSplunk
 
Splunk FISMA for Continuous Monitoring
Splunk FISMA for Continuous Monitoring Splunk FISMA for Continuous Monitoring
Splunk FISMA for Continuous Monitoring Greg Hanchin
 
Building Active Directory Monitoring with Telegraf, InfluxDB, and Grafana
Building Active Directory Monitoring with Telegraf, InfluxDB, and GrafanaBuilding Active Directory Monitoring with Telegraf, InfluxDB, and Grafana
Building Active Directory Monitoring with Telegraf, InfluxDB, and GrafanaBoni Yeamin
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkSolarWinds
 

Similar to Splunk for active_directory (20)

Splunk for xen_desktop
Splunk for xen_desktopSplunk for xen_desktop
Splunk for xen_desktop
 
Splunk Enterprise 6.1 Solutions Brief
Splunk Enterprise 6.1 Solutions BriefSplunk Enterprise 6.1 Solutions Brief
Splunk Enterprise 6.1 Solutions Brief
 
Office 365 Dashboards - Analytical Reporting Tools
Office 365 Dashboards - Analytical Reporting ToolsOffice 365 Dashboards - Analytical Reporting Tools
Office 365 Dashboards - Analytical Reporting Tools
 
Splunk for application_management
Splunk for application_managementSplunk for application_management
Splunk for application_management
 
Splunk sales presentation
Splunk sales presentationSplunk sales presentation
Splunk sales presentation
 
Splunk app for_windows
Splunk app for_windowsSplunk app for_windows
Splunk app for_windows
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
 
Splunk for exchange
Splunk for exchangeSplunk for exchange
Splunk for exchange
 
Splunk for exchange
Splunk for exchangeSplunk for exchange
Splunk for exchange
 
IRJET- Research Paper on Active Directory
IRJET-  	  Research Paper on Active DirectoryIRJET-  	  Research Paper on Active Directory
IRJET- Research Paper on Active Directory
 
Getting Started with Splunk
Getting Started with SplunkGetting Started with Splunk
Getting Started with Splunk
 
Active Directory Auditing and Reporting Tool
Active Directory Auditing and Reporting ToolActive Directory Auditing and Reporting Tool
Active Directory Auditing and Reporting Tool
 
FOISDBA-Ver1.1.pptx
FOISDBA-Ver1.1.pptxFOISDBA-Ver1.1.pptx
FOISDBA-Ver1.1.pptx
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
 
Splunk for f5
Splunk for f5Splunk for f5
Splunk for f5
 
Splunk
SplunkSplunk
Splunk
 
SplunkLive! Customer Presentation - Staples
SplunkLive! Customer Presentation - StaplesSplunkLive! Customer Presentation - Staples
SplunkLive! Customer Presentation - Staples
 
Splunk FISMA for Continuous Monitoring
Splunk FISMA for Continuous Monitoring Splunk FISMA for Continuous Monitoring
Splunk FISMA for Continuous Monitoring
 
Building Active Directory Monitoring with Telegraf, InfluxDB, and Grafana
Building Active Directory Monitoring with Telegraf, InfluxDB, and GrafanaBuilding Active Directory Monitoring with Telegraf, InfluxDB, and Grafana
Building Active Directory Monitoring with Telegraf, InfluxDB, and Grafana
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your Network
 

More from Greg Hanchin

NUTANIX and SPLUNK
NUTANIX and SPLUNKNUTANIX and SPLUNK
NUTANIX and SPLUNKGreg Hanchin
 
Splunk for cyber_threat
Splunk for cyber_threatSplunk for cyber_threat
Splunk for cyber_threatGreg Hanchin
 
Splunk for compliance
Splunk for complianceSplunk for compliance
Splunk for complianceGreg Hanchin
 
Splunk Searching and reporting 43course
Splunk Searching and reporting 43courseSplunk Searching and reporting 43course
Splunk Searching and reporting 43courseGreg Hanchin
 
Advanced Splunk 50 administration
Advanced Splunk 50 administrationAdvanced Splunk 50 administration
Advanced Splunk 50 administrationGreg Hanchin
 
Advanced searching and reporting 50 course
Advanced searching and reporting 50 course Advanced searching and reporting 50 course
Advanced searching and reporting 50 course Greg Hanchin
 
Administering splunk 43 course
Administering splunk 43 courseAdministering splunk 43 course
Administering splunk 43 courseGreg Hanchin
 
Using splunk43course
Using splunk43courseUsing splunk43course
Using splunk43courseGreg Hanchin
 
Using Splunk course outline
Using Splunk course outline Using Splunk course outline
Using Splunk course outline Greg Hanchin
 
Advanced Splunk Administration
Advanced Splunk AdministrationAdvanced Splunk Administration
Advanced Splunk AdministrationGreg Hanchin
 
Splunk Advanced searching and reporting Class description
Splunk Advanced searching and reporting Class descriptionSplunk Advanced searching and reporting Class description
Splunk Advanced searching and reporting Class descriptionGreg Hanchin
 
Administering Splunk course
Administering Splunk courseAdministering Splunk course
Administering Splunk courseGreg Hanchin
 
Splunk Searching and Reporting Class Details
Splunk Searching and Reporting Class DetailsSplunk Searching and Reporting Class Details
Splunk Searching and Reporting Class DetailsGreg Hanchin
 
Splunk forwarders tech_brief
Splunk forwarders tech_briefSplunk forwarders tech_brief
Splunk forwarders tech_briefGreg Hanchin
 
Splunk and map_reduce
Splunk and map_reduceSplunk and map_reduce
Splunk and map_reduceGreg Hanchin
 
Splunk for palo_alto
Splunk for palo_altoSplunk for palo_alto
Splunk for palo_altoGreg Hanchin
 
Splunk for db_connect
Splunk for db_connectSplunk for db_connect
Splunk for db_connectGreg Hanchin
 
Splunk app for_enterprise_security
Splunk app for_enterprise_securitySplunk app for_enterprise_security
Splunk app for_enterprise_securityGreg Hanchin
 

More from Greg Hanchin (20)

NUTANIX and SPLUNK
NUTANIX and SPLUNKNUTANIX and SPLUNK
NUTANIX and SPLUNK
 
Splunk for cyber_threat
Splunk for cyber_threatSplunk for cyber_threat
Splunk for cyber_threat
 
Splunk for compliance
Splunk for complianceSplunk for compliance
Splunk for compliance
 
Splunk Searching and reporting 43course
Splunk Searching and reporting 43courseSplunk Searching and reporting 43course
Splunk Searching and reporting 43course
 
Advanced Splunk 50 administration
Advanced Splunk 50 administrationAdvanced Splunk 50 administration
Advanced Splunk 50 administration
 
Advanced searching and reporting 50 course
Advanced searching and reporting 50 course Advanced searching and reporting 50 course
Advanced searching and reporting 50 course
 
Administering splunk 43 course
Administering splunk 43 courseAdministering splunk 43 course
Administering splunk 43 course
 
Using splunk43course
Using splunk43courseUsing splunk43course
Using splunk43course
 
Using Splunk course outline
Using Splunk course outline Using Splunk course outline
Using Splunk course outline
 
Advanced Splunk Administration
Advanced Splunk AdministrationAdvanced Splunk Administration
Advanced Splunk Administration
 
Splunk Advanced searching and reporting Class description
Splunk Advanced searching and reporting Class descriptionSplunk Advanced searching and reporting Class description
Splunk Advanced searching and reporting Class description
 
Administering Splunk course
Administering Splunk courseAdministering Splunk course
Administering Splunk course
 
Splunk Searching and Reporting Class Details
Splunk Searching and Reporting Class DetailsSplunk Searching and Reporting Class Details
Splunk Searching and Reporting Class Details
 
Splunk forwarders tech_brief
Splunk forwarders tech_briefSplunk forwarders tech_brief
Splunk forwarders tech_brief
 
Splunk and map_reduce
Splunk and map_reduceSplunk and map_reduce
Splunk and map_reduce
 
Splunk for palo_alto
Splunk for palo_altoSplunk for palo_alto
Splunk for palo_alto
 
Splunk for ibtrm
Splunk for ibtrmSplunk for ibtrm
Splunk for ibtrm
 
Splunk for fisma
Splunk for fismaSplunk for fisma
Splunk for fisma
 
Splunk for db_connect
Splunk for db_connectSplunk for db_connect
Splunk for db_connect
 
Splunk app for_enterprise_security
Splunk app for_enterprise_securitySplunk app for_enterprise_security
Splunk app for_enterprise_security
 

Splunk for active_directory

  • 1. Computer Account Information Site Information User Password and Account Information Organizational Unit Information Compliance Information Domain Information Domain Controllers DNS Server Active Directory With the Splunk App for Active Directory you can: • Monitor Active Directory Forest for potential security breaches and non-compliant usage patterns • Audit changes to group policies, user, group and computer objects in real time • View detailed topology statistics on all the objects of your Active Directory top down from the Forest to individual user and computer accounts • Monitor the operational health of Active Directory across site and domain boundaries Microsoft Windows Server Active Directory is the foundation of an IT infrastructure. It is the central location for user configuration information, authentication requests and information about all the computers that run your business. When issues occur in Active Directory, the effect is evident and widespread—users are unable to login, access privileges expire, e-mail stops flowing and websites hang, Organizations need a proactive, easy-to-deploy solution that will uncover the data needed to diagnose the issue, fix its root cause and restore service. Splunk App for Active Directory The Splunk App for Active Directory was designed to tackle the challenges faced by IT organizations—avoiding service outages, as well as proactive management and compliance reporting of the Active Directory infrastructure—from one place. This allows administrators to avoid the problems of traditional tools that just deliver health statistics, but miss reporting crucial compliance and auditing information. By monitoring the health and performance of an Active Directory Forest—from the forest, domains and sites that comprise the structure to the individual objects that represent tangible assets and then adding on compliance and auditing information—administrators can gain real-time operational intelligence about the entire Active Directory infrastructure. Armed with this deep insight from the data that is captured from Security, System and Audit logs, performance monitors and active service monitoring, your Active Directory Administrator can quickly pinpoint problems, identify security breaches and ensure corporate compliance goals. Real-time Monitoring and Auditing for Microsoft Windows Server Active Directory Splunk® App for Active Directory F A C T S H E E T Active Directory Data Inputs Active Directory Forest Topology Report • Real-time operational health and performance data of the Windows Server Active Directory Infrastructure • Integrated auditing features that track activity from root domains to the individual objects in a site • Extensive change management reports that deliver views to changes in objects and policies templates, increasing uptime H I G H L I G H T S
  • 2. www.splunk.com 250 Brannan St, San Francisco, CA, 94107 info@splunk.com | sales@splunk.com 866-438-7758 | 415-848-8400 www.splunkbase.com Copyright © 2012 Splunk Inc. All rights reserved. Splunk Enterprise is protected by U.S. and international copyright and intellectual property laws. Splunk is a registered trademark or trademark of Splunk Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies. Item # FS-Splunk-AppActiveDirectory-102 Product Requirements Supported Windows Server Versions The Splunk App for Active Directory supports Active Directory Forests running on Windows Server 2003 R2, Windows Server 2008, Windows Server 2008 R2 and Windows Server 2012. Splunk Requirements All instances of Splunk in a Splunk App for Active Directory requires Splunk Enterprise v4.3.2 or later and Sideview Utils v1.2.5 or later. All universal forwarders in a Splunk App for Active Directory deployment must run Splunk Enterprise v4.2.5 or later. F A C T S H E E T www.splunk.com 250 Brannan St, San Francisco, CA, 94107 info@splunk.com | sales@splunk.com 866-438-7758 | 415-848-8400 www.splunkbase.com Try Out the App, it’s Free! Go to www.splunk.com/microsoft to learn more. Splunk App for Active Directory Features The Splunk App for Active Directory provides several specialized features to monitor Active Directory, including: Topology Reports – Displays a complete view of the entire Active Directory Forest and the underlying Domains, Sites and Domain Controllers that are being monitored. This allows an Active Directory administrator to view the entire Forest from one single view rather then opening multiple consoles for information. Domain Services – Displays information on the Domains, Sites and Domain controllers that belong to the Active Directory Forest. The information here delivers real-time statistics as to how the individual components are operating and how they are working together. Information gathered here is used to troubleshoot login issues, account for missing object information due to replication failures, and monitor performance of the directory service and domain controller load. DNS Services – Displays information about the health, configuration, and performance of the DNS servers and DNS zones that host the Active Directory domains. Due to the dependency that Active Directory has on DNS, any changes made to DNS servers, performance issues or outages can create service disruptions on the Active Directory side. The information here allows Active Directory Administrators to view information about the DNS infrastructure that is usually administered by the networking team to see if issues in DNS are impacting the Active Directory Forest, producing faster resolution times. User Logon Failures – Displays failed attempts by users to log onto a specific domain in the Active Directory Forest. Information here is used to protect the Active Forest from malicious unauthorized login activities. From one console, administrators can then view the multiple ways a security breach may be attempted across the entire Forest. Anomalous Logons – Displays information on uncharacteristic usage patterns, such as a user logging in from multiple workstations. The information gathered here can be used to monitor for attempted security breaches across the Forest. User Utilization – Displays the user and workstation load managed by Active Directory Forest. Information here is used for monitoring the load Domain Controllers are carrying and can then be used to justify hardware and software acquisitions. Change Management – Displays changes made to objects in the Active Directory Forest. Helpdesk and admin staff can track changes made to computer accounts, domain accounts, organizational units and group policy objects to decrease support calls and pinpoint user issues. Free Download Download Splunk. You’ll get a Splunk Enterprise license for 60 days and you can index up to 500 megabytes of data per day. You can convert to a perpetual Free license or purchase an Enterprise license by contacting sales@splunk.com.