<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to collect Windows event logs without installing a universal forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287237#M54852</link>
    <description>&lt;P&gt;You can install Splunk Heavy Forwarder on a windows machine, collect WMI data and forward them to your Splunk Indexers running on RedHat 6.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2016 08:58:51 GMT</pubDate>
    <dc:creator>gmerhej_splunk</dc:creator>
    <dc:date>2016-04-11T08:58:51Z</dc:date>
    <item>
      <title>How to collect Windows event logs without installing a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287236#M54851</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I need to collect the logs from a Windows machine into Splunk without installing any agent (universal forwarder). I just wanted to know how to achieve this in Splunk 6.3 running on RedHat 6.&lt;/P&gt;

&lt;P&gt;With ref: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/MonitorWMIdata?r=searchtip"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/MonitorWMIdata?r=searchtip&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It says need to install Splunk Enterprise on Windows, but I don't want to install the any software on the servers since my client doesn't want to. So please let me know steps to achieve this.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 08:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287236#M54851</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2016-04-11T08:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect Windows event logs without installing a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287237#M54852</link>
      <description>&lt;P&gt;You can install Splunk Heavy Forwarder on a windows machine, collect WMI data and forward them to your Splunk Indexers running on RedHat 6.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 08:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287237#M54852</guid>
      <dc:creator>gmerhej_splunk</dc:creator>
      <dc:date>2016-04-11T08:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect Windows event logs without installing a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287238#M54853</link>
      <description>&lt;P&gt;can't we get without installing HF as well?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 10:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287238#M54853</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2016-04-11T10:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect Windows event logs without installing a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287239#M54854</link>
      <description>&lt;P&gt;You will need a Windows machine to collect WMI data.&lt;/P&gt;

&lt;P&gt;If your Splunk setup is non-Windows, you'll need a separate Windows instance running HF or UF. &lt;/P&gt;

&lt;P&gt;See the paragraph "Search Windows Data on a non-Windows Instance of Splunk Enterprise": &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/ConsiderationsfordecidinghowtomonitorWindowsdata#Polling_data_remotely_over_WMI.3F_Be_sure_to_read_this"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/ConsiderationsfordecidinghowtomonitorWindowsdata#Polling_data_remotely_over_WMI.3F_Be_sure_to_read_this&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you opt for a UF,  you cannot configure the WMI from the web interface but you can do the same through the wmi.conf: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/MonitorWMIdata"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/MonitorWMIdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 10:14:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287239#M54854</guid>
      <dc:creator>gmerhej_splunk</dc:creator>
      <dc:date>2016-04-11T10:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect Windows event logs without installing a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287240#M54855</link>
      <description>&lt;P&gt;Thanks for your information!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 10:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287240#M54855</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2016-04-11T10:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect Windows event logs without installing a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287241#M54856</link>
      <description>&lt;P&gt;Hi kpavan,&lt;/P&gt;

&lt;P&gt;You could try doing this &lt;BR /&gt;
&lt;A href="https://code.google.com/archive/p/eventlog-to-syslog/"&gt;https://code.google.com/archive/p/eventlog-to-syslog/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope it helps.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 13:16:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-Windows-event-logs-without-installing-a-universal/m-p/287241#M54856</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2016-04-11T13:16:30Z</dc:date>
    </item>
  </channel>
</rss>

