Download and configure the Splunk Add-ons for Windows DNS
This topic discusses how to download and configure the Splunk Add-ons for Windows DNS and deploy them to your deployment clients so that they forward Active Directory to the Splunk App for Microsoft Exchange indexer.
The Splunk App for Microsoft Exchange download package comes with a suite of add-ons that collect DNS data (as well as other data types.) When you deploy the add-ons to your DNS server deployment clients, the clients collect DNS data and forward it to the central Splunk App for Microsoft Exchange indexer.
More information about the DNS add-ons
The following table lists the DNS add-ons that come with the Splunk App for Microsoft Exchange, and what each add-on provides.
Add-on: | Description: |
---|---|
TA-DNSServer-NT5 | For DNS Servers that run Windows Server 2003/2003 R2 and earlier |
TA-DNSServer-NT6 | For DNS Servers that run Windows Server 2008/2008 R2 and later |
Download the Splunk Add-ons for Windows DNS
Like the Splunk Add-ons for Active Directory, the Splunk Add-ons for Windows DNS come with the Splunk App for Microsoft Exchange installation package.
If you have already completed the "Get Active Directory" portion of setup, you already have the Splunk App for Microsoft Exchange installation package and can skip this section.
Otherwise, you can download the Splunk App for Microsoft Exchange from Splunk Apps.
Download the app and save it to an accessible place on the deployment server:
1. In a web browser, proceed to the Splunk App for Microsoft Exchange download page.
2. Click the download link to begin the download process.
- Make sure you download the latest version of the app.
- You might need to sign in with your Splunk account before the download starts.
3. When prompted, choose an accessible location on your deployment server to save the download. Do not attempt to run the download.
4. Use an archive utility such as WinZip to unarchive the file to an accessible location.
Configure the Splunk Add-ons for Windows DNS
The Splunk Add-ons for Windows DNS do not require any configuration edits by default. When you deploy them onto the DNS servers, they immediately begin collecting data as long as you have configured DNS debug logging.
What's next?
You have downloaded the Splunk App for Microsoft Exchange and can now access the Splunk Add-ons for Window DNS. The next step involves deploying those add-ons into the deployment clients that you install on your Active Directory DNS servers.
Configure Windows Domain Name Server | Deploy the Splunk Add-ons for Windows DNS |
This documentation applies to the following versions of Splunk® App for Microsoft Exchange (EOL): 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.2.0, 3.2.1
Feedback submitted, thanks!