<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to send data to Splunk clsuters from Windows without UF in Security</title>
    <link>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/688749#M17888</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/54383"&gt;@payl_chdhry&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 27 May 2024 06:27:00 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-05-27T06:27:00Z</dc:date>
    <item>
      <title>How to send data to Splunk clsuters from Windows without UF</title>
      <link>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/553296#M12245</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am new to working without splunk agents/universal forwards for ingesting data into Splunk. I need to know how application can send data to Splunk indexer/HF, is there exact step provided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would it via HEC or by TCP port. And how could users set this up in this way to continuously send data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 09:57:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/553296#M12245</guid>
      <dc:creator>payl_chdhry</dc:creator>
      <dc:date>2021-05-27T09:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data to Splunk clsuters from Windows without UF</title>
      <link>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/553301#M12246</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/54383"&gt;@payl_chdhry&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you could use WMI to query Windows hosts and take logs, but I don't like this solution because you have to use an account with administrative privileges.&lt;/P&gt;&lt;P&gt;For more infos see&amp;nbsp; at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata&lt;/A&gt;&amp;nbsp;and &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/Data/MonitorWMIdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/Data/MonitorWMIdata&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;I hint to use everytime Universal Forwarders because this permits to you to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;filter unwanted logs on UF,&lt;/LI&gt;&lt;LI&gt;compress transmitted logs,&lt;/LI&gt;&lt;LI&gt;condifure max bandwidth occupation,&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;cash logs if there are problems on Indexers or Network.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you want to use WMI put this input in a dedicated Heavy Forwarder.&lt;/P&gt;&lt;P&gt;In addition you don't have HA because you have to configure only one HF at a time to vaoid to take logs twice.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 10:28:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/553301#M12246</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-05-27T10:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data to Splunk clsuters from Windows without UF</title>
      <link>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/553677#M12257</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN&gt;gcusello! We do not want to pull the logs, windows team would send the logs to us and they will take care of filtering out data if required. I am looking at enabling HEC on our Heavy forwards. I will create another question for this as I am a bit confused how it will work for clustered environment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Payal&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 05:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/553677#M12257</guid>
      <dc:creator>payl_chdhry</dc:creator>
      <dc:date>2021-05-31T05:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data to Splunk clsuters from Windows without UF</title>
      <link>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/553679#M12259</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/54383"&gt;@payl_chdhry&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you use HEC, you could put a Load Balancer in front of two Heavy Forwarders, so it distribute logs betweeen&amp;nbsp; the HFs and manage fail over and in this way you have an HA system to take logs from that UFs.&lt;/P&gt;&lt;P&gt;You could also use Indexers to take HEC logs but you need anyway a Load Balancer.&lt;/P&gt;&lt;P&gt;If you haven't a Load balancer, you can use a DNS configuration but it's less performant and in case of fail over, you lose the first logs.&lt;/P&gt;&lt;P&gt;At the end I hint to think again to your solution and take in consideration Universal Forwarders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 06:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/553679#M12259</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-05-31T06:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data to Splunk clsuters from Windows without UF</title>
      <link>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/688749#M17888</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/54383"&gt;@payl_chdhry&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 06:27:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-send-data-to-Splunk-clsuters-from-Windows-without-UF/m-p/688749#M17888</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-27T06:27:00Z</dc:date>
    </item>
  </channel>
</rss>

