<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I send Windows Event Forwarded events direct to Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370914#M67359</link>
    <description>&lt;P&gt;While there are a variety of ways to accomplish this, it seems the most obvious is &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.0/Data/MonitorWMIdata"&gt;to use WMI&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;While the UF is still faster and better, if you can't use the UF then using WMI can do a pretty good job of collecting data, especially from newer Windows machines (Windows ~8 and above I think?).&lt;/P&gt;

&lt;P&gt;You do have to use a Windows server with a full Splunk install on it to collect this data.  If your Splunk installation is *nix, you could just stand up one Splunk HF on Windows to use for this purpose.&lt;/P&gt;</description>
    <pubDate>Mon, 07 May 2018 01:42:17 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2018-05-07T01:42:17Z</dc:date>
    <item>
      <title>Can I send Windows Event Forwarded events direct to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370912#M67357</link>
      <description>&lt;P&gt;I heard a rumour that there was a Splunk Add-On that allowed it to act as a 'Windows Event Collector' Server, and so no need for a native Microsoft WEC Server. Is this true?&lt;/P&gt;

&lt;P&gt;I need to get events from a bunch of Windows 10 desktops and so look for options, if the above doesn't work I guess I will stand up a few WEC servers.&lt;/P&gt;

&lt;P&gt;And before anyone comments, no I can't use the Universal Forwarder because of contractual reasons.... Lets leave it at that!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 12:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370912#M67357</guid>
      <dc:creator>port7</dc:creator>
      <dc:date>2018-04-30T12:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can I send Windows Event Forwarded events direct to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370913#M67358</link>
      <description>&lt;P&gt;You can try &lt;CODE&gt;snare&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 13:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370913#M67358</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-04-30T13:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can I send Windows Event Forwarded events direct to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370914#M67359</link>
      <description>&lt;P&gt;While there are a variety of ways to accomplish this, it seems the most obvious is &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.0/Data/MonitorWMIdata"&gt;to use WMI&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;While the UF is still faster and better, if you can't use the UF then using WMI can do a pretty good job of collecting data, especially from newer Windows machines (Windows ~8 and above I think?).&lt;/P&gt;

&lt;P&gt;You do have to use a Windows server with a full Splunk install on it to collect this data.  If your Splunk installation is *nix, you could just stand up one Splunk HF on Windows to use for this purpose.&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 01:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370914#M67359</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2018-05-07T01:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can I send Windows Event Forwarded events direct to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370915#M67360</link>
      <description>&lt;P&gt;You can use snare or syslog servers to collect these logs and then use UF/HF from there to send them to splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 08:45:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370915#M67360</guid>
      <dc:creator>amitm05</dc:creator>
      <dc:date>2018-05-07T08:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can I send Windows Event Forwarded events direct to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370916#M67361</link>
      <description>&lt;P&gt;Why suggest WMI or Snare, if @port7 says he is planning to use Windows Event Forwarding? As far as I'm aware, WEF easily outperforms WMI when it comes to scalability and definitely outperforms Snare when it comes to data quality and making full use of all the CIM modelling in the Windows TA.&lt;/P&gt;

&lt;P&gt;His only question is whether he needs to set up a WIndows box configured as Windows Event Collector (and then run a Splunk Forwarder on that same box), or whether there is some Splunk add-on that allows Splunk to also take on the Windows Event Collector function.&lt;/P&gt;

&lt;P&gt;@port7: I've set up Windows log collection before using WEF where I configured a Windows server as the collector and then used a UF on that same box to monitor the forwarded events and send them into Splunk. I've never heard of an add-on that allows Splunk to act as the Collector directly (and a quick search on splunkbase and google also give me 0 results).&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 09:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370916#M67361</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-05-07T09:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can I send Windows Event Forwarded events direct to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370917#M67362</link>
      <description>&lt;P&gt;That's my finding too, I couldn't find any Splunk Add-On that can act as a collector for WEF events.&lt;/P&gt;

&lt;P&gt;It was suggested by a consultant from Microsoft, but I suspect they got their wires crossed.&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 10:03:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370917#M67362</guid>
      <dc:creator>port7</dc:creator>
      <dc:date>2018-05-07T10:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can I send Windows Event Forwarded events direct to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370918#M67363</link>
      <description>&lt;P&gt;Okay, I am assuming this is the same in 2019, and you can't set up Splunk to act as the WEF server, so I will do the same as you and throw a UF on my WEF server.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 17:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370918#M67363</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2019-08-01T17:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can I send Windows Event Forwarded events direct to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370919#M67364</link>
      <description>&lt;P&gt;What type of results are you getting with the UF on the WEF server ?&lt;BR /&gt;&lt;BR /&gt;
How many logs are you sending over ? Any latency issues ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 17:35:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-send-Windows-Event-Forwarded-events-direct-to-Splunk/m-p/370919#M67364</guid>
      <dc:creator>itrimble1</dc:creator>
      <dc:date>2019-08-20T17:35:41Z</dc:date>
    </item>
  </channel>
</rss>

