<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows 2008 R2 event subscriptions in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32352#M5742</link>
    <description>&lt;P&gt;I would think so (to some degree), but I'm not sure. However, I'm not sure why you would do that. Normally Splunk would be instaleld on a computer and forward directly to the indexer. If you used event subscriptions, you would essentially be forwarding from one computer to another (using event subscriptions) and then forwarding again to the indexer (using Splunk client). If you did use subscriptions you would probably also have to be careful in how you set Splunk to tag the events with hostnames, as all the events would appear to be coming from one computer.&lt;/P&gt;

&lt;P&gt;Hopefully someone else who has actually tried this will chime in.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Dec 2011 16:05:32 GMT</pubDate>
    <dc:creator>rtadams89</dc:creator>
    <dc:date>2011-12-09T16:05:32Z</dc:date>
    <item>
      <title>Windows 2008 R2 event subscriptions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32351#M5741</link>
      <description>&lt;P&gt;Do you know if Splunk supports event subscriptions ? It's a new feature on Windows 7 and Windows 2008 R2. It helps to centralize event logs from different Windows servers on one server.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc749183.aspx"&gt;http://technet.microsoft.com/en-us/library/cc749183.aspx&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2011 15:34:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32351#M5741</guid>
      <dc:creator>ysouchon</dc:creator>
      <dc:date>2011-12-09T15:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2008 R2 event subscriptions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32352#M5742</link>
      <description>&lt;P&gt;I would think so (to some degree), but I'm not sure. However, I'm not sure why you would do that. Normally Splunk would be instaleld on a computer and forward directly to the indexer. If you used event subscriptions, you would essentially be forwarding from one computer to another (using event subscriptions) and then forwarding again to the indexer (using Splunk client). If you did use subscriptions you would probably also have to be careful in how you set Splunk to tag the events with hostnames, as all the events would appear to be coming from one computer.&lt;/P&gt;

&lt;P&gt;Hopefully someone else who has actually tried this will chime in.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2011 16:05:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32352#M5742</guid>
      <dc:creator>rtadams89</dc:creator>
      <dc:date>2011-12-09T16:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2008 R2 event subscriptions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32353#M5743</link>
      <description>&lt;P&gt;Yes it does, but I'm finding the folks at Splunk either dont' ore won't tell you so they can sell you additional licesnes and/or technical services.&lt;/P&gt;

&lt;P&gt;Im my opinion you are much better off using the Windows subscription model for many reasons.  (But you milage may vary.)&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 19:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32353#M5743</guid>
      <dc:creator>Douggg</dc:creator>
      <dc:date>2013-12-12T19:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2008 R2 event subscriptions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32354#M5744</link>
      <description>&lt;P&gt;I can't see how this would play into the license size you would need. Whether you are sending the event log data from 10 hosts directly to Splunk, or aggregating it at an 11th host before sending it on to Splunk, the total log volume would be the same...&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 23:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32354#M5744</guid>
      <dc:creator>rtadams89</dc:creator>
      <dc:date>2013-12-12T23:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2008 R2 event subscriptions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32355#M5745</link>
      <description>&lt;P&gt;Splunk was doing 'event subscriptions' long before Microsoft was.  It is probably where Microsoft got the idea.&lt;/P&gt;

&lt;P&gt;Why do you want to go backwards?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2013 00:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32355#M5745</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-13T00:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2008 R2 event subscriptions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32356#M5746</link>
      <description>&lt;P&gt;Why?  Because you don't have to load Splunk's software.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2013 06:21:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32356#M5746</guid>
      <dc:creator>Douggg</dc:creator>
      <dc:date>2013-12-13T06:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2008 R2 event subscriptions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32357#M5747</link>
      <description>&lt;P&gt;The Splunk forwarders are free, and Windows subscriptions cannot consolidate network, unix, and any other non-Windows system.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2013 13:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-2008-R2-event-subscriptions/m-p/32357#M5747</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-13T13:14:14Z</dc:date>
    </item>
  </channel>
</rss>

