<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Windows Setup steps in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358187#M43387</link>
    <description>&lt;P&gt;Hi Jo,&lt;BR /&gt;
You don't need to reboot OS, only Splunk Forwarder.&lt;/P&gt;

&lt;P&gt;Sorry but examining your information, I see that you're running TA_Windows on a Unix system! TA_Windows must be installed on the target Windows server to monitor, not on the Splunk Enterprise Server!&lt;BR /&gt;
You can deploy it manually or using a Deployment Server, anyway it must run on a Windows server!&lt;/P&gt;

&lt;P&gt;See very carefully documentation at &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.1/Data/WhatSplunkcanmonitor" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.1/Data/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;

&lt;P&gt;P.S., if you're satisfied by my answer accept it.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 14:31:55 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-09-29T14:31:55Z</dc:date>
    <item>
      <title>Splunk Add-on for Windows Setup steps</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358182#M43382</link>
      <description>&lt;P&gt;Hi. &lt;BR /&gt;
I installed Splunk Add-on for Microsoft Windows version 4.8.4 from Splunk 6.5.3.&lt;BR /&gt;
However after installed this App, There on only message as like bellow:&lt;BR /&gt;
Overview&lt;/P&gt;

&lt;P&gt;The Splunk Add-on for Microsoft Windows provides pre-built data inputs to facilitate Windows system monitoring using Splunk. Check out the Splunk Add-on for Microsoft Windows page on Splunkbase for support information, the latest updates, and more.&lt;/P&gt;

&lt;P&gt;Configuration of inputs through this application are global, and might affect how other Splunk applications on the system use those inputs. After configuration, confirm that the changes you make in this application do not negatively alter the other applications.&lt;/P&gt;

&lt;P&gt;There are no available menu.&lt;BR /&gt;
Have you ever installed this apps successfully with my same situation?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Seung-Man Jo&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 06:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358182#M43382</guid>
      <dc:creator>seungman</dc:creator>
      <dc:date>2017-06-20T06:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows Setup steps</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358183#M43383</link>
      <description>&lt;P&gt;Hi seungman,&lt;BR /&gt;
did you followed instructions on &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/latest/User/AbouttheSplunkAdd-onforWindows"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/latest/User/AbouttheSplunkAdd-onforWindows&lt;/A&gt; ?&lt;BR /&gt;
Anyway, you have to analyze the scope of your monitoring and enable only inputs in your scope.&lt;BR /&gt;
To enable these inputs you have to modify inputs.conf file in $SPLUNK_HOME\etc\apps\local changing "1" with "0" in the "disabled" options.&lt;BR /&gt;
Remeber that if there isn't inputs.conf in local folder, you have to copy it from default folder, don't modify the one in default folder, because you'll lose your changes at the first upgrade.&lt;BR /&gt;
It's important to define the scope of your monitoring because Windows is very verbose and you could receive too many logs.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 07:10:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358183#M43383</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-06-20T07:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows Setup steps</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358184#M43384</link>
      <description>&lt;P&gt;Hi. cusello.&lt;BR /&gt;
After I installed Apps, there wasn`t inputs.conf file.&lt;BR /&gt;
Hence I created like below:&lt;BR /&gt;
[root@ip-172-31-28-27 local]# cat inputs.conf&lt;BR /&gt;
[WinEventLog://Security]&lt;BR /&gt;
index=security&lt;BR /&gt;
current_only=1&lt;BR /&gt;
evt_resolve_ad_obj=0&lt;BR /&gt;
renderXml=1&lt;BR /&gt;
disabled=0&lt;/P&gt;

&lt;P&gt;Is it correct inputs.conf file?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Seung-Man Jo&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:31:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358184#M43384</guid>
      <dc:creator>seungman</dc:creator>
      <dc:date>2020-09-29T14:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows Setup steps</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358185#M43385</link>
      <description>&lt;P&gt;Hi Jo,&lt;BR /&gt;
yes it's correct.&lt;BR /&gt;
Usually I prefer to use the default index "wineventlog" instead of a custom one, but you're correct, it's only a practice of mine.&lt;BR /&gt;
in addition I found that option "renderXml=1" sometimes gives an error and usually I don't use it: you can verify this restarting Splunk Forwarder by CLI, in this way you can see startup messages and eventually configuration errors.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 07:23:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358185#M43385</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-06-20T07:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows Setup steps</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358186#M43386</link>
      <description>&lt;P&gt;Hi. cusello.&lt;/P&gt;

&lt;P&gt;Thanks quick feedback.&lt;BR /&gt;
Yes. I deleted the 'renderXml=1' value and reboot OS also.&lt;BR /&gt;
However still same.&lt;BR /&gt;
Are there any check point?&lt;/P&gt;

&lt;P&gt;Here are my folder information.&lt;BR /&gt;
[root@ip-172-31-28-27 local]# ll&lt;BR /&gt;
total 8&lt;BR /&gt;
-rw------- 1 root root  65 Jun 20 05:26 app.conf&lt;BR /&gt;
-rw-r--r-- 1 root root 100 Jun 20 07:26 inputs.conf&lt;BR /&gt;
[root@ip-172-31-28-27 local]# pwd&lt;BR /&gt;
/etc/apps/splunk/etc/apps/Splunk_TA_windows/local&lt;BR /&gt;
[root@ip-172-31-28-27 local]#&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Seung-Man Jo&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:31:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358186#M43386</guid>
      <dc:creator>seungman</dc:creator>
      <dc:date>2020-09-29T14:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Windows Setup steps</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358187#M43387</link>
      <description>&lt;P&gt;Hi Jo,&lt;BR /&gt;
You don't need to reboot OS, only Splunk Forwarder.&lt;/P&gt;

&lt;P&gt;Sorry but examining your information, I see that you're running TA_Windows on a Unix system! TA_Windows must be installed on the target Windows server to monitor, not on the Splunk Enterprise Server!&lt;BR /&gt;
You can deploy it manually or using a Deployment Server, anyway it must run on a Windows server!&lt;/P&gt;

&lt;P&gt;See very carefully documentation at &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.1/Data/WhatSplunkcanmonitor" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.1/Data/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;

&lt;P&gt;P.S., if you're satisfied by my answer accept it.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Windows-Setup-steps/m-p/358187#M43387</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-29T14:31:55Z</dc:date>
    </item>
  </channel>
</rss>

