Refine your search:

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME/etc/apps. Then restart Splunk using the splunk restart command or the GUI.

Description

The Splunk for Windows technology add-on includes predefined inputs to collect data from Windows systems and maps to normalize the data to the Common Information Model.

The app includes a variety of inputs, including:

  • Windows event logs (security, system, application)
  • DHCP event log
  • Windows update logs
  • File change monitors for key Windows files
  • Listening ports
  • Installed applications
  • Performance metrics (CPU, Free Disk Space, Physical Disk, Memory, Network)
  • Scheduled Jobs
  • Installed Services
  • Windows uptime
  • User Account and SID information
  • Windows version information

Use this app to collect one or more of the data sources noted above for use with other Common Information Model compliant apps, including:

  • Splunk App for Enterprise Security
  • Splunk App for PCI Compliance v.2.0
  • Splunk for FISMA Getting Support

The Splunk for Windows Technology Add-on is a Splunk supported add-on.

If you have Splunk Enterprise support, please contact .

Versions and Release Notes

Version 4.6.2 (current version - updated Apr 07, 2013)
release notes:

Compatible with Splunk App for Windows; Modified to conform with add-on guidelines.

show older versions »
Version 4.6.1 (updated Nov 01, 2012)
release notes:

The app is compatible with Splunk 5.0.
WMI performance counters are disabled by default.

Version 4.6.0 (updated Aug 27, 2012)
release notes:

Version 4.6.0. Released 8/27/2012.

New in this release:
--------------------------
Common Information Model (CIM) changes to "patch/update" reporting.
Common Information Model (CIM) changes to "endpoint change" reporting.

For more see the ReadMe.txt

Copyright (C) 2005-2012 Splunk Inc. All Rights Reserved.

posted 12 Aug '11, 23:12

splunk's gravatar image

splunk
7.9k111
accept rate: 100%

new version 07 Apr, 19:02


2 Reviews:
2 reviews, 1 rating, average 5.0
Reviews related to version 4.6.1 (current is 4.6.2)

Right after installing this app, it tells you that it only works if installed on Windows. Don't install this app unless it's actually running on Windows. It needs to say this on the download page.

comments (0)

reviewed 30 Aug '12, 13:05

BWHarris's gravatar image

BWHarris
212
accept rate: 0%

edited 30 Aug '12, 13:06

Reviews related to version 4.6.0 (current is 4.6.2)

Is the Splunk for Windows app now compatible with this TA?

comments (0)

reviewed 04 May '12, 06:41

erga00's gravatar image

erga00
2282213
accept rate: 50%

Your review

Did you find this app useful?

Preview toggle preview

Copyright © 2005-2012 Splunk Inc. All rights reserved.