<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding logs from Windows Event Collector in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367215#M44386</link>
    <description>&lt;P&gt;There  are a couple of reasons I am trying to avoid that:&lt;BR /&gt;
a) the logs are already collected (for another purpose) from the clients on a Windows Event Collector server using the inbuilt Windows Event Forwarding. Collecting them again using a Universal Forwarder would just be doubling the load on those clients and "duplicating" the traffic.&lt;BR /&gt;
b) to avoid the administrative and cost overhead in organising the installation and update of the Forwarder in an environment managed by an outsourced provider.&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2017 05:25:55 GMT</pubDate>
    <dc:creator>paxos</dc:creator>
    <dc:date>2017-05-09T05:25:55Z</dc:date>
    <item>
      <title>Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367213#M44384</link>
      <description>&lt;P&gt;Is it possible to forward collected logs from a Windows Event Collector (WEC) server, i.e. from the Windows service that remotely collects logs from other windows servers, such that the logs are compatible with "Splunk App for Windows Infrastructure" ?&lt;/P&gt;

&lt;P&gt;I imagaine that at a minimum this would require "transforming" the default fields of host, source, sourcetype to meaningful values rather than the values that WEC uses. Would this then allow the events to be processed by the "Splunk Add-On for Windows" ?&lt;/P&gt;

&lt;P&gt;I know that the recommended method is to use a Universal Forwarder on all servers, or alternatively WMI, but as WEC has been around for a long time I am surprised there is no mention of it here ...&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/Data/AboutWindowsdataandSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/Data/AboutWindowsdataandSplunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Any information about anybody's experiences is much appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 10:59:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367213#M44384</guid>
      <dc:creator>paxos</dc:creator>
      <dc:date>2017-05-08T10:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367214#M44385</link>
      <description>&lt;P&gt;hello paxos,&lt;BR /&gt;
I must ask, why not use the Universal Forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 02:04:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367214#M44385</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-09T02:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367215#M44386</link>
      <description>&lt;P&gt;There  are a couple of reasons I am trying to avoid that:&lt;BR /&gt;
a) the logs are already collected (for another purpose) from the clients on a Windows Event Collector server using the inbuilt Windows Event Forwarding. Collecting them again using a Universal Forwarder would just be doubling the load on those clients and "duplicating" the traffic.&lt;BR /&gt;
b) to avoid the administrative and cost overhead in organising the installation and update of the Forwarder in an environment managed by an outsourced provider.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 05:25:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367215#M44386</guid>
      <dc:creator>paxos</dc:creator>
      <dc:date>2017-05-09T05:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367216#M44387</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Don't use Windows Event Collector&lt;/LI&gt;
&lt;LI&gt;Did you know that the event collector buffers events (tuning the buffers isn't an optimal solution either), adding a delay before Splunk receives the event. You may end up getting events a long time after they were generated&lt;/LI&gt;
&lt;LI&gt;Listen to me, don't use it. I've implemented solutions for several customers using WEC and it was just a waste of time&lt;/LI&gt;
&lt;LI&gt;Ok, you're persistent. See my answer on how to do it here: &lt;A href="https://answers.splunk.com/answers/213603/wineventlogforwardedevents-override.html#answer-330822"&gt;https://answers.splunk.com/answers/213603/wineventlogforwardedevents-override.html#answer-330822&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Ok, there may be a few good reasons to use WEC - such as preventing Splunk Forwarder from eating up all CPU and RAM because of poorly written runaway scripts. You may choose not to use those scripts. GOTO 1&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Mikael&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 06:01:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367216#M44387</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2017-05-09T06:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367217#M44388</link>
      <description>&lt;P&gt;Thanks. Just what I was looking for.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 16:01:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367217#M44388</guid>
      <dc:creator>paxos</dc:creator>
      <dc:date>2017-05-09T16:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367218#M44389</link>
      <description>&lt;P&gt;Hi @mikaelbje, what would you recommend instead of using Windows Event Collectors? Is the alternative simply installing a universal forwarder on every endpoint? &lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 20:49:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367218#M44389</guid>
      <dc:creator>dillardo_2</dc:creator>
      <dc:date>2019-08-21T20:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367219#M44390</link>
      <description>&lt;P&gt;What did you end up going with ?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 16:40:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367219#M44390</guid>
      <dc:creator>itrimble1</dc:creator>
      <dc:date>2019-08-22T16:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367220#M44391</link>
      <description>&lt;P&gt;@mikaelbje &lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 16:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/367220#M44391</guid>
      <dc:creator>dillardo_2</dc:creator>
      <dc:date>2019-08-22T16:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/512001#M62752</link>
      <description>&lt;P&gt;I would also like to know what's recommended.&amp;nbsp; Are people really installing Splunk Universal Forwarder on every endpoint?&amp;nbsp; &amp;nbsp;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 02:11:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/512001#M62752</guid>
      <dc:creator>bharrell</dc:creator>
      <dc:date>2020-08-01T02:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding logs from Windows Event Collector</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/579578#M75819</link>
      <description>&lt;P&gt;any other method to collect logs other than wec.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 10:45:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarding-logs-from-Windows-Event-Collector/m-p/579578#M75819</guid>
      <dc:creator>engrimranzakir</dc:creator>
      <dc:date>2021-12-30T10:45:13Z</dc:date>
    </item>
  </channel>
</rss>

