<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to enable WMI data collection on a Domain Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13867#M1289</link>
    <description>&lt;P&gt;Thanks, I'll try it soon!&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2010 20:37:42 GMT</pubDate>
    <dc:creator>pmelchiori</dc:creator>
    <dc:date>2010-07-14T20:37:42Z</dc:date>
    <item>
      <title>How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13855#M1277</link>
      <description>&lt;P&gt;Hi, I've a problem with the &lt;A href="http://www.splunk.com/base/Documentation/4.1.1/Admin/MonitorWMIdata" rel="nofollow"&gt;WMI privilege&lt;/A&gt; on a Domain Controller running Win 2003 R2. This is what I done:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Add user to the groups &lt;STRONG&gt;Performance Log Users&lt;/STRONG&gt; and &lt;STRONG&gt;Distributed COM Users Domain groups&lt;/STRONG&gt;. &lt;/LI&gt;
&lt;LI&gt;Add Splunk's user to the &lt;STRONG&gt;Distributed COM Users local group&lt;/STRONG&gt; &lt;/LI&gt;
&lt;LI&gt;Enabled all permissions on the &lt;STRONG&gt;WMI&lt;/STRONG&gt; tree at root for the Splunk user.&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;no &lt;STRONG&gt;firewall&lt;/STRONG&gt; between the pc and the server.&lt;/P&gt;

&lt;P&gt;I can't add my special user to the administrator's group, but if I do everyting works correctly.&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;There are other Group Policy to enable? other setting to change? thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 14:15:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13855#M1277</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2010-05-19T14:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13856#M1278</link>
      <description>&lt;P&gt;I don't understand what you mean by "you can't add" but "it works correctly" if you do. You mean you are not allowed to, and you are trying to see if there is another way to do it besides adding the user to to group?&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 16:24:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13856#M1278</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-19T16:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13857#M1279</link>
      <description>&lt;P&gt;Looking at MSDN: &lt;A href="http://msdn.microsoft.com/en-us/library/aa389290%28v=VS.85%29.aspx" rel="nofollow"&gt;http://msdn.microsoft.com/en-us/library/aa389290%28v=VS.85%29.aspx&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;"...Windows Server 2003, Windows XP, and Windows 2000:  The account on Computer B must be in the Administrator group, but a domain account is not required...."&lt;/P&gt;

&lt;P&gt;From this document it sounds like the user running Splunk has to be in the Administrative group to be able to connect to WMI remotely.  The same user context that Splunk is running as will be used to log in to remote box and connect to WMI&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2010 08:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13857#M1279</guid>
      <dc:creator>Ledio_Ago</dc:creator>
      <dc:date>2010-05-20T08:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13858#M1280</link>
      <description>&lt;P&gt;Well, but note that if the computer is a DC, then the Administrator group &lt;EM&gt;is&lt;/EM&gt; the Domain Administrator group.&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2010 13:22:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13858#M1280</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-20T13:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13859#M1281</link>
      <description>&lt;P&gt;Exactly, I try to put in the Administrators group, and it works fine, but the system administrator doesn't give me the permission to use forever this way.&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2010 14:04:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13859#M1281</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2010-05-20T14:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13860#M1282</link>
      <description>&lt;P&gt;This is the main point!&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2010 17:45:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13860#M1282</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2010-05-20T17:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13861#M1283</link>
      <description>&lt;P&gt;Sorry, this sounds like that's what Windows requires. It does not entirely surprise me. It is possible that you can fiddle around with settings in the DCOMCNFG.EXE application to make it work with a non-Administrator group, but this is something probably more readily answered at a Windows-specialist site.&lt;/P&gt;</description>
      <pubDate>Sat, 22 May 2010 14:36:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13861#M1283</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-22T14:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13862#M1284</link>
      <description>&lt;P&gt;I've already give to my user the DCOM permission! The only think is that quen I test the WMI the answer to the query is empty! not an error...&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2010 14:29:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13862#M1284</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2010-05-24T14:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13863#M1285</link>
      <description>&lt;P&gt;You have to run Splunk with an account that has local Administrator privileges.  See &lt;A href="http://www.splunk.com/base/Documentation/latest/Installation/InstallonWindowsviathecommandline#Choosing_the_user_Splunk_should_run_as" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Installation/InstallonWindowsviathecommandline#Choosing_the_user_Splunk_should_run_as&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2010 05:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13863#M1285</guid>
      <dc:creator>igor</dc:creator>
      <dc:date>2010-06-12T05:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13864#M1286</link>
      <description>&lt;P&gt;DC server doesn't have the Local Admins!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2010 15:15:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13864#M1286</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2010-06-14T15:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13865#M1287</link>
      <description>&lt;P&gt;In my experience, if you have an AD user that is a member of the DC's "Domain Admin" group, processes that run as the AD user will run with local Administrators group privilege as well.  I suggest adding the "Domain Admin" group to that user and trying again.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2010 01:23:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13865#M1287</guid>
      <dc:creator>igor</dc:creator>
      <dc:date>2010-06-15T01:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13866#M1288</link>
      <description>&lt;P&gt;Add the user the following:&lt;/P&gt;

&lt;P&gt;Add User to the groups &lt;STRONG&gt;Performance Log Users&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Add User to the Group of &lt;STRONG&gt;Distributed COM Users&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Open &lt;STRONG&gt;Local Security Policy&lt;/STRONG&gt; (Start -&amp;gt; All Programs -&amp;gt; Administrative Tools -&amp;gt; Local Security Policy)&lt;/P&gt;

&lt;P&gt;Select -&amp;gt; &lt;STRONG&gt;Secutiy Settings -&amp;gt; Local Policies -&amp;gt; User Rights Assignment -&amp;gt; Manage Auditing and Security Log&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Add the user to that policy &lt;STRONG&gt;Manage Auditing and Security Log&lt;/STRONG&gt;, that will solve your problem.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2010 16:15:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13866#M1288</guid>
      <dc:creator>klkumar10</dc:creator>
      <dc:date>2010-07-13T16:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13867#M1289</link>
      <description>&lt;P&gt;Thanks, I'll try it soon!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2010 20:37:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13867#M1289</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2010-07-14T20:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13868#M1290</link>
      <description>&lt;P&gt;Done, nothing changes... any other ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2010 20:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13868#M1290</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2010-07-15T20:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13869#M1291</link>
      <description>&lt;P&gt;I had a similar question.&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;See also the answers I got:&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/questions/4226/splunk-on-a-domain-controller" rel="nofollow"&gt;http://answers.splunk.com/questions/4226/splunk-on-a-domain-controller&lt;/A&gt;&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;Hope it's also useful for you.&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2010 19:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13869#M1291</guid>
      <dc:creator>simuvid</dc:creator>
      <dc:date>2010-07-27T19:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13870#M1292</link>
      <description>&lt;P&gt;Saw that many answers revolve around adding the account to the Local Administrators group on the DC. This is indeed possible on a 2003 DC. Simply add the user to the BUILTIN\Administrators group on the DC. &lt;/P&gt;

&lt;P&gt;One thing to note is that the Domain Admins group is a member of BUILTIN\Administrators group, so if you already added the account to Domain Admins the account should have (out of the box) loca admin privs on the DC.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2010 21:17:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13870#M1292</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-07-27T21:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13871#M1293</link>
      <description>&lt;P&gt;Just got done reading through the convoluted stream of answers and comments again. &lt;/P&gt;

&lt;P&gt;To sum it up, your problem is:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;If you add the account to the Domain Admin group, you can poll WMI fine, but your sysadmin does not allow this configuration.&lt;/LI&gt;
&lt;LI&gt;You followed the &lt;A href="http://www.splunk.com/base/Documentation/4.1.4/Admin/MonitorWMIdata" rel="nofollow"&gt;manual&lt;/A&gt; in setting this up for a non admin account&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Now when you say it doesn't work, do you mean querying via &lt;CODE&gt;splunk cmd splunk-wmi -wql "select * from win32_service" -namespace \\&amp;lt;server&amp;gt;\root\cimv2&lt;/CODE&gt; or via  a different method? If you run the splunk cmd, do you receive an error? If so, can you please post that error?&lt;/P&gt;

&lt;P&gt;If you are not getting anything, or rather, if you are getting something similar to this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then you probably left the initial &lt;CODE&gt;splunk&lt;/CODE&gt; off of the &lt;CODE&gt;splunk cmd&lt;/CODE&gt; command and just invoked another shell with &lt;CODE&gt;cmd&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Please also post details on the account you are running the polling splunk instance as. Domain account, local account, local SYSTEM account?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2010 21:36:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13871#M1293</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-07-27T21:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13872#M1294</link>
      <description>&lt;P&gt;I can't add my user to the administrators group, company policy.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2010 17:33:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13872#M1294</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2010-08-10T17:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13873#M1295</link>
      <description>&lt;P&gt;Thanks ftk, this is the result:&lt;/P&gt;

&lt;P&gt;ERROR WMI - Error occurred while trying to retrive results from a WMI query (error="Call failed." HRESULT=80041001) (.: select * from win32_service)&lt;BR /&gt;
ERROR WMI - Giving up attempt to connect to WMI provider after maximum number of retries at maximum backoff time (.: select * from win32_service)&lt;/P&gt;

&lt;P&gt;Clean shutdown completed&lt;/P&gt;

&lt;P&gt;Instead, with the administrator's account, everything works fine.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:15:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13873#M1295</guid>
      <dc:creator>pmelchiori</dc:creator>
      <dc:date>2020-09-28T09:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable WMI data collection on a Domain Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13874#M1296</link>
      <description>&lt;P&gt;So I've been working specifically on unraveling the mystery around this, and after a bit of trial and error, this is the solution I have come up with to get it working.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;First I made a domain group that will have the access I have assigned.  Always better to do this because you never want to assign users to local member server (or domain controller) groups, or hang users directly on ACLs, it's a PITA security-wise and will assuredly bite you in the rear-end later.  I'll call this group &lt;STRONG&gt;Splunkers&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Then, I put the Splunk user into this group.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Then, I started assigning permissions.  &lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;First place to start: Putting the newly created &lt;STRONG&gt;Splunkers&lt;/STRONG&gt; group in the appropriate domain groups (as shown above):&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Performance Log Users&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Distributed COM Users&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Next: Assign &lt;STRONG&gt;Splunkers&lt;/STRONG&gt; some rights.  Since this is a domain controller, you need to run the Default Domain Controller Security Settings snap-in (dcpol.msc).&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Once inside, expand &lt;STRONG&gt;Security Settings&lt;/STRONG&gt;, then &lt;STRONG&gt;Local Policies&lt;/STRONG&gt;, and finally &lt;STRONG&gt;User Rights Assignment&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Assign your new group &lt;STRONG&gt;at least&lt;/STRONG&gt; the following rights:
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Act as part of the operating system&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Log on as a batch job&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Log on as a service&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Replace a process level token&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Okay, now you need to set DCOM security.  Start up &lt;STRONG&gt;Component Services&lt;/STRONG&gt; from &lt;STRONG&gt;Start, -&amp;gt; Administrative Tools&lt;/STRONG&gt;.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Once there, expand &lt;STRONG&gt;Console Root&lt;/STRONG&gt;, then &lt;STRONG&gt;Computers&lt;/STRONG&gt;, and finally &lt;STRONG&gt;My Computer&lt;/STRONG&gt;. Right-click on &lt;STRONG&gt;My Computer&lt;/STRONG&gt; and select &lt;STRONG&gt;"Properties..."&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;In the window that appears, click on the &lt;STRONG&gt;COM Security&lt;/STRONG&gt; tab.&lt;/LI&gt;
&lt;LI&gt;Then, under "Access Permissions," click &lt;STRONG&gt;Edit Limits.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Review that the &lt;STRONG&gt;Distributed COM Users&lt;/STRONG&gt; group has all items checked under &lt;STRONG&gt;Allow.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;At this point, you &lt;EM&gt;can&lt;/EM&gt; add your new domain group &lt;STRONG&gt;Splunkers&lt;/STRONG&gt; to this list and ensure that they have full Allow access as well, but it is not required, since &lt;STRONG&gt;Splunkers&lt;/STRONG&gt; is a member of &lt;STRONG&gt;Distributed COM Users&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Once you've reviewed or added the group, click OK to save your changes and be returned back to the COM Security tab.&lt;/LI&gt;
&lt;LI&gt;Now, under "Launch and Activation Permissions", click &lt;STRONG&gt;Edit Limits.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Like with the "Access Permissions" window, you are presented with a number of groups and permissions.  You need to make sure that the &lt;STRONG&gt;Distributed COM Users&lt;/STRONG&gt; group has all items checked under &lt;STRONG&gt;Allow.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;If you want, you can also add the &lt;STRONG&gt;Splunkers&lt;/STRONG&gt; group here, and assign full Allow access.  It is not required, since &lt;STRONG&gt;Splunkers&lt;/STRONG&gt; is already a member of &lt;STRONG&gt;Distributed COM Users.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Click OK to save your changes.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;All right, next, you need to set WMI namespace security. From the Start menu, select &lt;STRONG&gt;Run...&lt;/STRONG&gt;, and in the window that opens, type in &lt;STRONG&gt;wmimgmt.msc&lt;/STRONG&gt; in the "Open:" field and click OK.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Once there, right-click on &lt;STRONG&gt;WMI Control (Local)&lt;/STRONG&gt; and click &lt;STRONG&gt;Properties&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Click on the &lt;STRONG&gt;Security&lt;/STRONG&gt; tab.&lt;/LI&gt;
&lt;LI&gt;Click on the &lt;STRONG&gt;Security&lt;/STRONG&gt; button at the bottom right of the window.  This action edits the security settings for the &lt;STRONG&gt;Root&lt;/STRONG&gt; WMI namespace.&lt;/LI&gt;
&lt;LI&gt;You'll now see a window that has the security settings for WMI on this machine. Click &lt;STRONG&gt;Advanced...&lt;/STRONG&gt; Yes, you need to do this. &lt;/LI&gt;
&lt;LI&gt;You'll now see the Advanced security settings for this WMI namespace.  You'll need to add the &lt;STRONG&gt;Splunkers&lt;/STRONG&gt; group to the list, and give &lt;STRONG&gt;at least&lt;/STRONG&gt; the following "Allow" permissions:
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Execute Methods&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Enable Account&lt;/LI&gt;
&lt;LI&gt;Remote Enable&lt;/LI&gt;
&lt;LI&gt;Read Security&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;Then, you need to make sure that these permissions apply to this namespace and all the namespaces under it.  Do that by selecting &lt;STRONG&gt;This namespace and subnamespaces&lt;/STRONG&gt; in the dropdown box above the permissions list.&lt;/LI&gt;
&lt;LI&gt;Click OK to save the new permissions.&lt;/LI&gt;
&lt;LI&gt;Then, click OK again to exit out of the Advanced Security Settings.&lt;/LI&gt;
&lt;LI&gt;Click OK a third time to exit the security properties.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Now that you've set WMI namespace security, make sure that you've disabled Windows Firewall/ICS services on both the Splunk server and the server you wish to get data from over WMI.&lt;/P&gt;

&lt;P&gt;Once you've done all that, you will need to bounce Splunk. After Splunk has been restarted, you should then be able to create WMI data inputs off of your domain controller.&lt;/P&gt;

&lt;P&gt;A few notes about this:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;I've tested this on a Windows 2003 R2 DC with Windows 2003 member servers running the Splunk service.  With Windows 2008, things are a little different (think UAC).  I'm working on what else needs to be done to get this running in Windows 2008.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;There's no non-esoteric way at this time to globally configure WMI security settings domain-wide.  Each machine has its own setting.  There is &lt;A href="http://blogs.msdn.com/spatdsg/archive/2007/11/21/set-wmi-namespace-security-via-gpo-script.aspx" rel="nofollow"&gt;an MSDN blog,&lt;/A&gt; however, that lists the steps you can take to create a script that contains the appropriate security descriptors, which you can then subsequently throw into a GPO as a startup script and have your computers get the updated security settings at boot time.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;If you're collecting event logs over WMI - and, in particular, the Security event log - you'll need to enable access to that log on the machine you're collecting the logs from.  This is not trivial (think, SDDL knowledge and INF file edits if you're thinking about putting it in a GPO).&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 12 Jan 2011 06:28:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-enable-WMI-data-collection-on-a-Domain-Server/m-p/13874#M1296</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2011-01-12T06:28:27Z</dc:date>
    </item>
  </channel>
</rss>

