<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WMI Log Collection in Security</title>
    <link>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17257#M13659</link>
    <description>&lt;P&gt;C:\Program Files\Splunk\bin\scripts\splunk-wmi.py does not exist.  I'm a newbie, shouldn't that have been there as part of the install?  Where would I find that file or add it to the directory?
Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2010 02:35:10 GMT</pubDate>
    <dc:creator>ricksimonds</dc:creator>
    <dc:date>2010-07-14T02:35:10Z</dc:date>
    <item>
      <title>WMI Log Collection</title>
      <link>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17255#M13657</link>
      <description>&lt;P&gt;Splunk is installed in a Windows Domain.  The service accounts are running as a Domain Admin. The authentication for the Web Manager is LDAP and is logged into using Domain Admin cridentials.&lt;/P&gt;

&lt;P&gt;WEBTEST is successful from a cmd line.  When I configure remote Windows Log collection via WMI I get the following errors:&lt;/P&gt;

&lt;P&gt;07-12-2010 15:08:09.033 ERROR AdminManager - Unexpected error "" from python handler: "winmgmts:{impersonationLevel=impersonate,authenticationLevel=default}//ServerName/.Win32_NTEventlogFile".  See splunkd.log for more details.
07-12-2010 15:08:43.745 ERROR ExecProcessor - message from "python "C:\Program Files\Splunk\bin\scripts\splunk-wmi.py"" python: can't open file 'C:\Program Files\Splunk\bin\scripts\splunk-wmi.py': [Errno 2] No such file or directory&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2010 02:39:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17255#M13657</guid>
      <dc:creator>ricksimonds</dc:creator>
      <dc:date>2010-07-13T02:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Log Collection</title>
      <link>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17256#M13658</link>
      <description>&lt;P&gt;I guess, first of all, does that file &lt;CODE&gt;C:\Program Files\Splunk\bin\scripts\splunk-wmi.py&lt;/CODE&gt; exist? If so, who owns it, and does the Splunk user have sufficient access all the way up to the file? If you changed the service account after installation, it's likely/probably that some file permissions are too restricted to the original account.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2010 02:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17256#M13658</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-07-13T02:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Log Collection</title>
      <link>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17257#M13659</link>
      <description>&lt;P&gt;C:\Program Files\Splunk\bin\scripts\splunk-wmi.py does not exist.  I'm a newbie, shouldn't that have been there as part of the install?  Where would I find that file or add it to the directory?
Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2010 02:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17257#M13659</guid>
      <dc:creator>ricksimonds</dc:creator>
      <dc:date>2010-07-14T02:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: WMI Log Collection</title>
      <link>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17258#M13660</link>
      <description>&lt;P&gt;The splunk-wmi.py file gets installed when you install the Splunk Windows App. Enable the app from the launcher app.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2010 19:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/WMI-Log-Collection/m-p/17258#M13660</guid>
      <dc:creator>mneethling</dc:creator>
      <dc:date>2010-08-11T19:31:55Z</dc:date>
    </item>
  </channel>
</rss>

