<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to use WMI on a Windows universal forwarder and send it to indexers and search heads running Linux? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148476#M30196</link>
    <description>&lt;P&gt;I'm guessing you attempted to configure Remote event log collections from a linux box.&lt;/P&gt;

&lt;P&gt;Here's what I did: Start up an ancient Windows VM, dropped in a copy of Splunk 6.1.4 and ran an install. &lt;BR /&gt;
Once installed, I went to Settings &amp;gt; Data Inputs and chose Remote event log collections. &lt;BR /&gt;
I configured a remote connection in the UI, which updates a couple .conf files and restarted the services.&lt;BR /&gt;
I verified data was coming into the instance.&lt;/P&gt;

&lt;P&gt;Now I have a choice:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I can turn my full Splunk instance into a Light or Heavy forwarder, point it at the indexer, and let that instance poll other nodes over WMI and forward the data. &lt;/LI&gt;
&lt;LI&gt;I can collect all the .conf file pieces, and place them into a pre-configred Windows Universal forwarder installation.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;You can read about the different forwarders &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Forwarding/Typesofforwarders"&gt;here&lt;/A&gt;. &lt;BR /&gt;
You can review common troubleshooting tips for WMI connections &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Troubleshooting/TroubleshootingWMI"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Oct 2014 17:41:24 GMT</pubDate>
    <dc:creator>ekost</dc:creator>
    <dc:date>2014-10-02T17:41:24Z</dc:date>
    <item>
      <title>Is it possible to use WMI on a Windows universal forwarder and send it to indexers and search heads running Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148471#M30191</link>
      <description>&lt;P&gt;I currently am running splunk enterprise on a Linux Distribution (Red Hat).  I am following the guide to import WMI data to splunk, and there is no "Remote event log collections".  &lt;/P&gt;

&lt;P&gt;Deployment: Linux&lt;BR /&gt;
Forwarder: Windows 7 (64 bit)&lt;/P&gt;

&lt;P&gt;Is it possible to use WMI on a Windows forwarder and send it to indexer / search heads running linux?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 18:58:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148471#M30191</guid>
      <dc:creator>smvalois</dc:creator>
      <dc:date>2014-10-01T18:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use WMI on a Windows universal forwarder and send it to indexers and search heads running Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148472#M30192</link>
      <description>&lt;P&gt;Yes, you can use a forwarder to collect data via WMI and send the results to a linux-based Splunk instance. Check the table &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/MonitorWMIData#What.27s_required_to_monitor_WMI-based_data.3F"&gt;here&lt;/A&gt; for what is required to monitor hosts using WMI. That topic includes a &lt;CODE&gt;wmi.conf&lt;/CODE&gt; &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/MonitorWMIData#Examples_of_wmi.conf"&gt;example&lt;/A&gt;. The reasons for collecting data via WMI instead of using forwarders must be evaluated and the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/ConsiderationsfordecidinghowtomonitorWindowsdata#Splunk_forwarders_versus_WMI"&gt;trade-offs&lt;/A&gt; reviewed.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 20:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148472#M30192</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2014-10-01T20:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use WMI on a Windows universal forwarder and send it to indexers and search heads running Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148473#M30193</link>
      <description>&lt;P&gt;We operate in an environment where agents are viewed as evil.  I do not personally agree with that, but will take the wins where I can get them.  According to that table, splunk enterprise must be running on windows.  My linux enterprise version does not list "Remote Event Log Collections" as an option under data inputs.  Is there an addon I have to install?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 14:00:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148473#M30193</guid>
      <dc:creator>smvalois</dc:creator>
      <dc:date>2014-10-02T14:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use WMI on a Windows universal forwarder and send it to indexers and search heads running Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148474#M30194</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;snip of @ekost's answer: Yes, you can &lt;STRONG&gt;use a forwarder&lt;/STRONG&gt; to collect data via WMI and send the results to a linux-based Splunk instance.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 14:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148474#M30194</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-10-02T14:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use WMI on a Windows universal forwarder and send it to indexers and search heads running Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148475#M30195</link>
      <description>&lt;P&gt;Sorry, I know I sound like a broken record here.  The issue is following the instructions to get this setup.  The link is here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/MonitorWindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/MonitorWindowsdata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Under "Configure remote event log monitoring", it says go to Data Inputs and click Remote Event Log Collections.  That option is not there.  All I have is TCP, UDP, Local File and Scripts.  Is there something else I need to install for that to show up?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 15:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148475#M30195</guid>
      <dc:creator>smvalois</dc:creator>
      <dc:date>2014-10-02T15:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use WMI on a Windows universal forwarder and send it to indexers and search heads running Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148476#M30196</link>
      <description>&lt;P&gt;I'm guessing you attempted to configure Remote event log collections from a linux box.&lt;/P&gt;

&lt;P&gt;Here's what I did: Start up an ancient Windows VM, dropped in a copy of Splunk 6.1.4 and ran an install. &lt;BR /&gt;
Once installed, I went to Settings &amp;gt; Data Inputs and chose Remote event log collections. &lt;BR /&gt;
I configured a remote connection in the UI, which updates a couple .conf files and restarted the services.&lt;BR /&gt;
I verified data was coming into the instance.&lt;/P&gt;

&lt;P&gt;Now I have a choice:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I can turn my full Splunk instance into a Light or Heavy forwarder, point it at the indexer, and let that instance poll other nodes over WMI and forward the data. &lt;/LI&gt;
&lt;LI&gt;I can collect all the .conf file pieces, and place them into a pre-configred Windows Universal forwarder installation.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;You can read about the different forwarders &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Forwarding/Typesofforwarders"&gt;here&lt;/A&gt;. &lt;BR /&gt;
You can review common troubleshooting tips for WMI connections &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Troubleshooting/TroubleshootingWMI"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 17:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148476#M30196</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2014-10-02T17:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use WMI on a Windows universal forwarder and send it to indexers and search heads running Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148477#M30197</link>
      <description>&lt;P&gt;Thank you,  this is similar to the method I used as well.  I basically made the WMI.conf file on my windows forwarder (dropping a full version would have probably been much easier).  &lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 18:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-use-WMI-on-a-Windows-universal-forwarder-and/m-p/148477#M30197</guid>
      <dc:creator>smvalois</dc:creator>
      <dc:date>2014-10-02T18:42:29Z</dc:date>
    </item>
  </channel>
</rss>

