<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forwarding remote WMI information in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-remote-WMI-information/m-p/19352#M2743</link>
    <description>&lt;P&gt;I need to configure a universal forwarder to remotely collect WMI information (eventlogs) from various Windows hosts, and then forward that information to my indexer.  I have the universal forwarder up and running, and it is successfully forwarding local information to my indexer. &lt;/P&gt;

&lt;P&gt;I believe I need to write a WMI.conf file, but I don't know what to put in it.  Can someone post an example of what it should look like, or tell me if I should be using a light forwarder instead?&lt;/P&gt;

&lt;P&gt;Thank you.  &lt;/P&gt;</description>
    <pubDate>Thu, 05 Apr 2012 00:37:06 GMT</pubDate>
    <dc:creator>fnsbsd</dc:creator>
    <dc:date>2012-04-05T00:37:06Z</dc:date>
    <item>
      <title>Forwarding remote WMI information</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-remote-WMI-information/m-p/19352#M2743</link>
      <description>&lt;P&gt;I need to configure a universal forwarder to remotely collect WMI information (eventlogs) from various Windows hosts, and then forward that information to my indexer.  I have the universal forwarder up and running, and it is successfully forwarding local information to my indexer. &lt;/P&gt;

&lt;P&gt;I believe I need to write a WMI.conf file, but I don't know what to put in it.  Can someone post an example of what it should look like, or tell me if I should be using a light forwarder instead?&lt;/P&gt;

&lt;P&gt;Thank you.  &lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2012 00:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-remote-WMI-information/m-p/19352#M2743</guid>
      <dc:creator>fnsbsd</dc:creator>
      <dc:date>2012-04-05T00:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding remote WMI information</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-remote-WMI-information/m-p/19353#M2744</link>
      <description>&lt;P&gt;if you download to your UF the &lt;A href="http://splunk-base.splunk.com/apps/28933/splunk-for-windows-technology-add-on"&gt;Splunk for Windows technology add-on&lt;/A&gt; it has, in default folder, a wmi.conf with examples ie:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WMI:LocalSecurity]
interval = 10
event_log_file = Security
index = default
disabled = 0

[WMI:LocalProcesses]
interval = 30
wql = SELECT Name, IDProcess, PrivateBytes, PercentProcessorTime FROM Win32_PerfFormattedData_PerfProc_Process
index = default
disabled = 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 05 Apr 2012 10:15:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-remote-WMI-information/m-p/19353#M2744</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-04-05T10:15:40Z</dc:date>
    </item>
  </channel>
</rss>

