Refine your search:

Hi Splunkers,

I am very new to Splunk and would like to monitor Windows servers, how do I configure the Windows boxes to send their event data over to Splunk indexer? The indexer is installed in a Linux environment. Installing a Splunk forwarder on each Windows box does not seam to be a good option at my place.

Thank you for your advice.

asked 24 Jan, 13:01

tomero2011's gravatar image

tomero2011
11
accept rate: 0%


One Answer:

If you can't install the Splunk forwarder on the Windows boxes, can you: set up a Windows box and install a Splunk Forwarder on it, and then configure that Splunk forwarder to do remote event log collection or WMI?

Only a Windows machine can collect event logs or WMI.

This is not considered the best practice, but it will work. And, over time, perhaps you can install the Splunk Universal Forwarder on the various Windows boxes.

link

answered 24 Jan, 19:59

lguinn's gravatar image

lguinn ♦
3.1k216
accept rate: 24%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×303
×109
×2
×2

Asked: 24 Jan, 13:01

Seen: 516 times

Last updated: 24 Jan, 19:59

Copyright © 2005-2012 Splunk, Inc. All rights reserved.