<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it recommended to install Universal Forwarder on all Workstations? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-recommended-to-install-Universal-Forwarder-on-all/m-p/300793#M56866</link>
    <description>&lt;P&gt;some thing related answer:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/499611/how-to-monitor-remote-logs-in-a-centerized-heavy-f.html"&gt;https://answers.splunk.com/answers/499611/how-to-monitor-remote-logs-in-a-centerized-heavy-f.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2017 20:03:07 GMT</pubDate>
    <dc:creator>mpreddy</dc:creator>
    <dc:date>2017-02-15T20:03:07Z</dc:date>
    <item>
      <title>Is it recommended to install Universal Forwarder on all Workstations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-recommended-to-install-Universal-Forwarder-on-all/m-p/300792#M56865</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Is it the best way to install Universal Forwarders on all Workstations and enable windows security events , Right Now I have UF's on all DC's?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 19:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-recommended-to-install-Universal-Forwarder-on-all/m-p/300792#M56865</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2017-02-15T19:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Is it recommended to install Universal Forwarder on all Workstations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-recommended-to-install-Universal-Forwarder-on-all/m-p/300793#M56866</link>
      <description>&lt;P&gt;some thing related answer:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/499611/how-to-monitor-remote-logs-in-a-centerized-heavy-f.html"&gt;https://answers.splunk.com/answers/499611/how-to-monitor-remote-logs-in-a-centerized-heavy-f.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 20:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-recommended-to-install-Universal-Forwarder-on-all/m-p/300793#M56866</guid>
      <dc:creator>mpreddy</dc:creator>
      <dc:date>2017-02-15T20:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is it recommended to install Universal Forwarder on all Workstations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-recommended-to-install-Universal-Forwarder-on-all/m-p/300794#M56867</link>
      <description>&lt;P&gt;If your asking "is there value" in installing the UF on workstations the answer is almost certainly "yes"&lt;/P&gt;

&lt;P&gt;But you should consider a few things first:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Monitoring your DCs will show you failed/successful domain logins, but they may not include all the security relevant events, such as all attempts using local credentials or local file/device access.&lt;/LI&gt;
&lt;LI&gt;With the UF on your workstations you can also start to monitor application logs, or with SplunkStream even wireline traffic for remote diagnostics etc.&lt;/LI&gt;
&lt;LI&gt;But - you can easily start collecting huge amounts of data, so be sure your indexer disk (or your index management) has been spec'd to cope - and most importantly consider the size of your licence!&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 15 Feb 2017 20:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-recommended-to-install-Universal-Forwarder-on-all/m-p/300794#M56867</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-02-15T20:24:06Z</dc:date>
    </item>
  </channel>
</rss>

