<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor Windows event log via WMI to splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647282#M110071</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257819"&gt;@splk_user&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2023 12:08:24 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-06-16T12:08:24Z</dc:date>
    <item>
      <title>Monitor Windows event log via WMI to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647251#M110058</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it possible to monitor Windows event log via WMI to splunk instead of using Universal Forwarder?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;if yes, how can i configure this communication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 08:26:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647251#M110058</guid>
      <dc:creator>splk_user</dc:creator>
      <dc:date>2023-06-16T08:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Windows event log via WMI to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647252#M110059</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257819"&gt;@splk_user&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes it's possible even if I try to avoid to use WMI because you must use a domain user to acces the remote systems.&lt;/P&gt;&lt;P&gt;In addition a Universal Forwarder gives you many additional feature like local caching, packets compression, bandwidth optimization, etc...&lt;/P&gt;&lt;P&gt;Anyway, here you can find the procedure to configure a WMI input:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.5/Data/MonitorWMIdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.5/Data/MonitorWMIdata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 08:37:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647252#M110059</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-16T08:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Windows event log via WMI to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647255#M110060</link>
      <description>&lt;P&gt;You can use WMI to pull EventLog from remote computer but you sitll have to install that windows splunk component which will be doing the pulling (UF or HF) somewhere.&lt;/P&gt;&lt;P&gt;There are several methods of collecting windows EventLogs.&lt;/P&gt;&lt;P&gt;The easiest and most straightforward way is to install UF on a monitored server and pull events directly from local eventlog. But it might create issues of scalability and windows admins might not be thrilled if you want to install third-party tools on domain controllers or other important servers.&lt;/P&gt;&lt;P&gt;Another relatively well working idea is to use Windows Event Forwarding (easy to set up in a domain environment, can be also confuigured in domainless setup but then it gets complicated but still possible) and pull windows from a central eventlog collector. I use it quite a lot. Be aware of possible performance issues as you scale horizontally too far.&lt;/P&gt;&lt;P&gt;WMI can be used to pull from remote computers but that's generally a last resort solution. Performance is not very good, you _must_ run the UF with domain account (which implies that it can only be used in domain environment) and there are often issues with permissions/privileges so it might be tricky to set up unless you have a very good windows admin team.&lt;/P&gt;&lt;P&gt;The solution which can be used but honestly speaking should never even be considered is using a third party forwarder (typically a syslog one like kiwi, solarwinds or nxlog). This way you might relatively easily get your logs and syslog is easy to receive but the events you get this way will be horribly mangled and not suitable for typical slplunk-side processing (meaning they will not be understandable by TA-windows).&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 09:10:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647255#M110060</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-06-16T09:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Windows event log via WMI to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647280#M110069</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 12:07:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647280#M110069</guid>
      <dc:creator>splk_user</dc:creator>
      <dc:date>2023-06-16T12:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Windows event log via WMI to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647281#M110070</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 12:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647281#M110070</guid>
      <dc:creator>splk_user</dc:creator>
      <dc:date>2023-06-16T12:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Windows event log via WMI to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647282#M110071</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257819"&gt;@splk_user&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 12:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/647282#M110071</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-16T12:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Windows event log via WMI to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/660251#M111650</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was reading this reply and I am currently in need to set up this from your post.&lt;/P&gt;&lt;P&gt;==============&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Another relatively well working idea is to use Windows Event Forwarding (easy to set up in a domain environment, can be also confuigured in domainless setup but then it gets complicated but still possible) and pull windows from a central eventlog collector. I use it quite a lot. Be aware of possible performance issues as you scale horizontally too far.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;===========&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Do you have any&amp;nbsp; guide/link which tells this step by step; how to setup WEF on two servers.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 15:25:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-event-log-via-WMI-to-splunk/m-p/660251#M111650</guid>
      <dc:creator>asharma</dc:creator>
      <dc:date>2023-10-10T15:25:52Z</dc:date>
    </item>
  </channel>
</rss>

