<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk deployment on Laptop/Desktop in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-deployment-on-Laptop-Desktop/m-p/583739#M10384</link>
    <description>&lt;P&gt;Hell all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my organzation we are trying to collect logs from all Laptop/Desktop into Splunk. I read somewhere that we can use logs collected from AV agents instead of installing universal forwarders. I We have CrowdStrike agents on all our endpoint devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;s this right method? If so, what is the use cases where we may have to install UF on endpoint devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 04 Feb 2022 15:44:21 GMT</pubDate>
    <dc:creator>I29851</dc:creator>
    <dc:date>2022-02-04T15:44:21Z</dc:date>
    <item>
      <title>Splunk deployment on Laptop/Desktop</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-deployment-on-Laptop-Desktop/m-p/583739#M10384</link>
      <description>&lt;P&gt;Hell all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my organzation we are trying to collect logs from all Laptop/Desktop into Splunk. I read somewhere that we can use logs collected from AV agents instead of installing universal forwarders. I We have CrowdStrike agents on all our endpoint devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;s this right method? If so, what is the use cases where we may have to install UF on endpoint devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 15:44:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-deployment-on-Laptop-Desktop/m-p/583739#M10384</guid>
      <dc:creator>I29851</dc:creator>
      <dc:date>2022-02-04T15:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk deployment on Laptop/Desktop</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-deployment-on-Laptop-Desktop/m-p/584677#M10385</link>
      <description>&lt;P&gt;I think it all depends on what data you want to collect.&lt;/P&gt;&lt;P&gt;For example, you just need anti-virus logs, you can use CrowdStrike Add-on from Splunkbase and that should give you anti-virus-related logs.&lt;/P&gt;&lt;P&gt;If you also want WinEventLogs from Windows endpoints, you have to either install UF or you can use Windows' functionality of WinEventLog forwarding.&lt;/P&gt;&lt;P&gt;But if you have some files located on endpoints which you want to monitor (its very rare, but in case) then the best option is to install UF.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 08:40:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-deployment-on-Laptop-Desktop/m-p/584677#M10385</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-02-11T08:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk deployment on Laptop/Desktop</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-deployment-on-Laptop-Desktop/m-p/584683#M10386</link>
      <description>&lt;P&gt;The possible issue with third-party solutions for windows event log retrieving is that they often will be in some format that's not understandable by the standard Windows Add-on so you'd have to invest much time and effort to either normalize the events&amp;nbsp; yourself and make them CIM-compliant or convert them to a typical Windows Event format.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 09:00:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-deployment-on-Laptop-Desktop/m-p/584683#M10386</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-11T09:00:20Z</dc:date>
    </item>
  </channel>
</rss>

