<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I send Windows Event logs to Splunk Indexer installed in Linux? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-Event-logs-to-Splunk-Indexer-installed-in/m-p/57035#M11134</link>
    <description>&lt;P&gt;If you can't install the Splunk forwarder on the Windows boxes, can you: set up a Windows box and install a Splunk Forwarder on it, and then configure that Splunk forwarder to do remote event log collection or WMI?&lt;/P&gt;

&lt;P&gt;Only a Windows machine can collect event logs or WMI.&lt;/P&gt;

&lt;P&gt;This is not considered the best practice, but it will work. And, over time, perhaps you can  install the Splunk Universal Forwarder on the various Windows boxes.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2012 03:59:42 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2012-01-25T03:59:42Z</dc:date>
    <item>
      <title>How do I send Windows Event logs to Splunk Indexer installed in Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-Event-logs-to-Splunk-Indexer-installed-in/m-p/57034#M11133</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;I am very new to Splunk and would like to monitor Windows servers, how do I configure the Windows boxes to send their event data over to Splunk indexer? The indexer is installed in a Linux environment. Installing a Splunk forwarder on each Windows box does not seam to be a good option at my place.&lt;/P&gt;

&lt;P&gt;Thank you for your advice.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 21:01:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-Event-logs-to-Splunk-Indexer-installed-in/m-p/57034#M11133</guid>
      <dc:creator>tomero2011</dc:creator>
      <dc:date>2012-01-24T21:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send Windows Event logs to Splunk Indexer installed in Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-Event-logs-to-Splunk-Indexer-installed-in/m-p/57035#M11134</link>
      <description>&lt;P&gt;If you can't install the Splunk forwarder on the Windows boxes, can you: set up a Windows box and install a Splunk Forwarder on it, and then configure that Splunk forwarder to do remote event log collection or WMI?&lt;/P&gt;

&lt;P&gt;Only a Windows machine can collect event logs or WMI.&lt;/P&gt;

&lt;P&gt;This is not considered the best practice, but it will work. And, over time, perhaps you can  install the Splunk Universal Forwarder on the various Windows boxes.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 03:59:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-Event-logs-to-Splunk-Indexer-installed-in/m-p/57035#M11134</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-01-25T03:59:42Z</dc:date>
    </item>
  </channel>
</rss>

