<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the best practice for collecting Windows Event Logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264270#M50694</link>
    <description>&lt;P&gt;Thanks for the reply adauria.  Your response &lt;EM&gt;somewhat&lt;/EM&gt; answers my question.  &lt;/P&gt;

&lt;P&gt;One clarification, since WMI can be executed locally by the Splunk Universal Forwarder, my question leans more toward a performance best practice for collecting local event log data. &lt;/P&gt;

&lt;P&gt;The original subject of the query was more along those lines however a Splunk moderator changed the subject so it doesn't really reflect the type of information for which I'm looking.&lt;/P&gt;

&lt;P&gt;Basically, is the &lt;CODE&gt;WinEventLog&lt;/CODE&gt; method of collecting event logs more or less efficient (in terms of system overhead) than using WMI and &lt;CODE&gt;event_log_file&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Thanks again&lt;/P&gt;</description>
    <pubDate>Sun, 12 Feb 2017 23:01:40 GMT</pubDate>
    <dc:creator>arechenberg</dc:creator>
    <dc:date>2017-02-12T23:01:40Z</dc:date>
    <item>
      <title>What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264265#M50689</link>
      <description>&lt;P&gt;Windows event logs can be gathered both via &lt;CODE&gt;WinEventLog&lt;/CODE&gt; in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and also via WMI and &lt;CODE&gt;event_log_file&lt;/CODE&gt; in &lt;CODE&gt;wmi.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Does anyone have a best practice for collecting Windows event logs?  Which method incurs more of an overhead on the system?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2017 17:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264265#M50689</guid>
      <dc:creator>arechenberg</dc:creator>
      <dc:date>2017-01-30T17:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264266#M50690</link>
      <description>&lt;P&gt;I usually prefer wineventlog using Splunk Add-on for Windows deployed using a Deployment Server&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe &lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2017 17:22:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264266#M50690</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-01-30T17:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264267#M50691</link>
      <description>&lt;P&gt;Thanks for the response Giuseppe.  Are you able to provide rationale for preferring this method over WMI?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2017 18:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264267#M50691</guid>
      <dc:creator>arechenberg</dc:creator>
      <dc:date>2017-01-30T18:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264268#M50692</link>
      <description>&lt;P&gt;Security and performance issues with wmi are pretty well documented on the internet - not Splunk's implementation, per se, but in general. Even if those aren't relevant in your deployment, most Splunk apps that rely on Windows event data are looking for it in the format gathered with the standard WinEventLog method. &lt;/P&gt;

&lt;P&gt;I will echo the previous reply and suggest that you use the standard Splunk Windows technical add on (TA) as the prefer method of collecting Windows data. WMI is best suited to situations were you cannot install a universal forwarder and you already have a WMI infrastructure in place. &lt;/P&gt;

&lt;P&gt;You can also think of it like this: WinEventLog is for collecting events locally generated on the host with the universal forwarder, while WMI can be used for remote event collection from Windows systems that can't install a forwarder for whatever reason. &lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 12:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264268#M50692</guid>
      <dc:creator>adauria_splunk</dc:creator>
      <dc:date>2017-01-31T12:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264269#M50693</link>
      <description>&lt;P&gt;@arechenberg - Did one of the answers below help provide a solution your question? If yes, please click “Accept” below the best answer to resolve this post and upvote anything that was helpful. If no, please leave a comment with more feedback. Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2017 07:22:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264269#M50693</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-02-12T07:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264270#M50694</link>
      <description>&lt;P&gt;Thanks for the reply adauria.  Your response &lt;EM&gt;somewhat&lt;/EM&gt; answers my question.  &lt;/P&gt;

&lt;P&gt;One clarification, since WMI can be executed locally by the Splunk Universal Forwarder, my question leans more toward a performance best practice for collecting local event log data. &lt;/P&gt;

&lt;P&gt;The original subject of the query was more along those lines however a Splunk moderator changed the subject so it doesn't really reflect the type of information for which I'm looking.&lt;/P&gt;

&lt;P&gt;Basically, is the &lt;CODE&gt;WinEventLog&lt;/CODE&gt; method of collecting event logs more or less efficient (in terms of system overhead) than using WMI and &lt;CODE&gt;event_log_file&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2017 23:01:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264270#M50694</guid>
      <dc:creator>arechenberg</dc:creator>
      <dc:date>2017-02-12T23:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264271#M50695</link>
      <description>&lt;P&gt;WinEventLog is almost always going to be preferred over WMI. The only advantage WMI has is that it supports remote event collection. On the local system running a Universal Forward, WinEventLog is going to be more efficient and provide events in a format compatible with more of apps that use it on Splunkbase. &lt;/P&gt;

&lt;P&gt;You should also consider using the Splunk Windows Technology Add-On (TA) for Windows event collection. This add on is a plug in to the Universal Forward that collect Windows events as well as other optional elements (e.g. perfmon counters, etc.). It uses the WinEventLog format. Again, besides the performance benefits of collecting events directly (as opposed to WMI, local or otherwise), it delivers events to your Splunk server(s) in a format compatibility with most of the Splunkbase apps that rely on Windows events.  &lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2017 23:31:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264271#M50695</guid>
      <dc:creator>adauria_splunk</dc:creator>
      <dc:date>2017-02-12T23:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264272#M50696</link>
      <description>&lt;P&gt;I guess you are looking for this link - &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 05:53:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264272#M50696</guid>
      <dc:creator>satishsdange</dc:creator>
      <dc:date>2017-02-13T05:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for collecting Windows Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264273#M50697</link>
      <description>&lt;P&gt;Further supporting this point is the inclusion of this topic over in the docs within the &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata"&gt;Considerations for deciding how to monitor remote Windows data&lt;/A&gt; page. See the sections &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata#Splunk_forwarders_versus_WMI"&gt;Splunk forwarders versus WMI&lt;/A&gt; and &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/ConsiderationsfordecidinghowtomonitorWindowsdata#Use_a_forwarder_to_collect_remote_Windows_data"&gt;Use a forwarder to collect remote Windows data&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 20:30:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-collecting-Windows-Event-Logs/m-p/264273#M50697</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-04-12T20:30:20Z</dc:date>
    </item>
  </channel>
</rss>

