<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder Data Input recommendations for Windows servers - different roles in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101034#M21157</link>
    <description>&lt;P&gt;Snare si fine, but I do recommend, whenever is possible, to use a Universal Forwarder on the Windows servers to send logs to Splunk indexers, because you can take advantage of Forwarder's functionality like load balancing, consistency of logs sent in case of communication failures or in the indexer is down, just to mention some. &lt;BR /&gt;
Moreover, using a forwarder, you have native recognition of events coming from WinEventlog. &lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2013 07:24:47 GMT</pubDate>
    <dc:creator>marcoscala</dc:creator>
    <dc:date>2013-05-30T07:24:47Z</dc:date>
    <item>
      <title>Forwarder Data Input recommendations for Windows servers - different roles</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101032#M21155</link>
      <description>&lt;P&gt;Best recomended practices - Data Input config for Windows servers with the following roles
IIS - SQL - Domain Controllers - Sharepoint  - Exchnage &lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2010 05:37:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101032#M21155</guid>
      <dc:creator>oneashraf</dc:creator>
      <dc:date>2010-12-08T05:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data Input recommendations for Windows servers - different roles</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101033#M21156</link>
      <description>&lt;P&gt;I'm going to assume you are using some type of log forwarder to send these logs to splunk. I am using Snare on my windows servers. It allows me to tell it to send logs on any port I choose. For my DHCP Server, I'm having it send logs to splunk using port 516. On Splunk, I've configured a Data Input, UDP port 516, SourceType: from list, Windows Snare Syslog.&lt;/P&gt;

&lt;P&gt;It formats it perfectly. I guess you could do that for each Server.   &lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2010 06:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101033#M21156</guid>
      <dc:creator>mayler</dc:creator>
      <dc:date>2010-12-08T06:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data Input recommendations for Windows servers - different roles</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101034#M21157</link>
      <description>&lt;P&gt;Snare si fine, but I do recommend, whenever is possible, to use a Universal Forwarder on the Windows servers to send logs to Splunk indexers, because you can take advantage of Forwarder's functionality like load balancing, consistency of logs sent in case of communication failures or in the indexer is down, just to mention some. &lt;BR /&gt;
Moreover, using a forwarder, you have native recognition of events coming from WinEventlog. &lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2013 07:24:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101034#M21157</guid>
      <dc:creator>marcoscala</dc:creator>
      <dc:date>2013-05-30T07:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Data Input recommendations for Windows servers - different roles</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101035#M21158</link>
      <description>&lt;P&gt;I agree with the comments so far.  I just want to expand just a little more.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;install the Universal Forwarder on the target Windows machines&lt;/LI&gt;
&lt;LI&gt;Install the Windows app and see how much milage that gets you in monitoring the rest; also look at the Exchange and SQL apps as well
Browse the aforementioned apps directory structure explore such things as the inputs and savedsearches conf files to see how all this is working behind the scenes.  Feel free to copy and paste these searches in the search bar and modify/tweak to gain additional insights into your data.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;For more fine tuning, consider this:&lt;BR /&gt;
 - the application inputs SQL, IIS, Exchange, etc can get real chatty...that's both good and bad.  Here is my suggestion on this:&lt;BR /&gt;
 Create a test-msft index and send your data from a couple of servers to that index for a couple of days.  What you are looking for is what data is mere noise vs insights.  You create a test index so that once you get the data you like coming in, you point it to either your default index or another index; afterwards, delete the test index.  (this is a common practice for me)&lt;/P&gt;

&lt;P&gt;Install the Deployment Monitor and the SoS apps to monitor what you will be doing next.&lt;/P&gt;

&lt;H2&gt;Grooming your data:  &lt;/H2&gt;

&lt;P&gt;This will be done using the inputs.conf file one each forwarder.  Here's the link: &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/admin/Inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you feel the need to throttle the amount of data being indexed, add information to the "whitelist" and "blacklist" sections.  This restricts/ allows what data will be forwarded to the indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2013 19:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-Data-Input-recommendations-for-Windows-servers/m-p/101035#M21158</guid>
      <dc:creator>barakreeves</dc:creator>
      <dc:date>2013-05-31T19:46:05Z</dc:date>
    </item>
  </channel>
</rss>

