<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: On Windows, can I use different credentials to pull WinEvents via WMI? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/On-Windows-can-I-use-different-credentials-to-pull-WinEvents-via/m-p/30534#M5348</link>
    <description>&lt;P&gt;Splunk uses the account it runs under to pull remote WMI.&lt;/P&gt;

&lt;P&gt;You have the following options available for remote WMI at this point:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;In a multi domain scenario you
ideally would configure domain or
even forest level trust relationships
so that your splunk service account
can accees remote WMI across domain
boundaries.&lt;/LI&gt;
&lt;LI&gt;In a workgroup scenario you can create accounts on the remote machines that are identically named to the splunk service account and have the same password. Remote WMI will then work with this account.&lt;/LI&gt;
&lt;LI&gt;You could try to create your own scripted input. For example you could create a PowerShell script that pulls the remote WMI events using credentials different from the splunk service account.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If domain trusts and in a workgroup scenario identical logins aren't an option, then forwarders, custom scripted inputs, or forwarding the events via syslog (e.g. winlogd) are your only options. Separate WMI credentials within splunk sound like a great ER though.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Aug 2010 22:10:47 GMT</pubDate>
    <dc:creator>ftk</dc:creator>
    <dc:date>2010-08-16T22:10:47Z</dc:date>
    <item>
      <title>On Windows, can I use different credentials to pull WinEvents via WMI?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/On-Windows-can-I-use-different-credentials-to-pull-WinEvents-via/m-p/30533#M5347</link>
      <description>&lt;P&gt;Does Splunk have the ability to use different sets of credentials for different monitoring on Windows? &lt;/P&gt;

&lt;P&gt;It appears only one credential can be used for WMI to pull Windows events from across the environment and no local credentials can be used. &lt;/P&gt;

&lt;P&gt;For instance, if I have Windows machines on several different domains as well as local DMZ workgroups, I will probably have one than one user account (they won't all be the same). &lt;/P&gt;

&lt;P&gt;Also, we may not have the ability to deploy agents out as LWFs, just so you know.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2010 20:40:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/On-Windows-can-I-use-different-credentials-to-pull-WinEvents-via/m-p/30533#M5347</guid>
      <dc:creator>maverick</dc:creator>
      <dc:date>2010-08-16T20:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: On Windows, can I use different credentials to pull WinEvents via WMI?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/On-Windows-can-I-use-different-credentials-to-pull-WinEvents-via/m-p/30534#M5348</link>
      <description>&lt;P&gt;Splunk uses the account it runs under to pull remote WMI.&lt;/P&gt;

&lt;P&gt;You have the following options available for remote WMI at this point:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;In a multi domain scenario you
ideally would configure domain or
even forest level trust relationships
so that your splunk service account
can accees remote WMI across domain
boundaries.&lt;/LI&gt;
&lt;LI&gt;In a workgroup scenario you can create accounts on the remote machines that are identically named to the splunk service account and have the same password. Remote WMI will then work with this account.&lt;/LI&gt;
&lt;LI&gt;You could try to create your own scripted input. For example you could create a PowerShell script that pulls the remote WMI events using credentials different from the splunk service account.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If domain trusts and in a workgroup scenario identical logins aren't an option, then forwarders, custom scripted inputs, or forwarding the events via syslog (e.g. winlogd) are your only options. Separate WMI credentials within splunk sound like a great ER though.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2010 22:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/On-Windows-can-I-use-different-credentials-to-pull-WinEvents-via/m-p/30534#M5348</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-08-16T22:10:47Z</dc:date>
    </item>
  </channel>
</rss>

