<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WMI - How many remote Windows can a Splunk WMI input support? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WMI-How-many-remote-Windows-can-a-Splunk-WMI-input-support/m-p/37893#M6963</link>
    <description>&lt;P&gt;It depends on how busy the remote hosts are.  As a rule of thumb, one Splunk instance (forwarder or indexer) can support the collection of Security Event Logs (the most verbose variety) on between 20 and 50 remote hosts.  To scale out collection on more remote hosts, simply add another Splunk instance (forwarder or indexer) to collect another from another 20 to 50 remote hosts.  Rinse and repeat.&lt;/P&gt;

&lt;P&gt;All that said, I would strongly recomment installing the Splunk Forwarder, a relatively lightweight build of Splunk that has no UI and no indexing, on your hosts rather than using WMI.  Beyond better resiliance by collecting Event Logs and other WMI data remotely, you will be able to easily collect and forward other data such as DNS, DHCP, Windows Update, and application logs.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Apr 2012 07:17:24 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2012-04-27T07:17:24Z</dc:date>
    <item>
      <title>WMI - How many remote Windows can a Splunk WMI input support?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WMI-How-many-remote-Windows-can-a-Splunk-WMI-input-support/m-p/37892#M6962</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I am planning to monitor many Windows client via WMI interface.&lt;BR /&gt;
I have one Splunk installed on Windows7.&lt;BR /&gt;
How many remote Windows can a Splunk WMI input support?&lt;BR /&gt;
Do we have any estimation calculation about the number of max number of target windows hosts?&lt;BR /&gt;
10s, 100s, or 1000s windows hosts?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2012 01:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WMI-How-many-remote-Windows-can-a-Splunk-WMI-input-support/m-p/37892#M6962</guid>
      <dc:creator>melonman</dc:creator>
      <dc:date>2012-04-27T01:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: WMI - How many remote Windows can a Splunk WMI input support?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WMI-How-many-remote-Windows-can-a-Splunk-WMI-input-support/m-p/37893#M6963</link>
      <description>&lt;P&gt;It depends on how busy the remote hosts are.  As a rule of thumb, one Splunk instance (forwarder or indexer) can support the collection of Security Event Logs (the most verbose variety) on between 20 and 50 remote hosts.  To scale out collection on more remote hosts, simply add another Splunk instance (forwarder or indexer) to collect another from another 20 to 50 remote hosts.  Rinse and repeat.&lt;/P&gt;

&lt;P&gt;All that said, I would strongly recomment installing the Splunk Forwarder, a relatively lightweight build of Splunk that has no UI and no indexing, on your hosts rather than using WMI.  Beyond better resiliance by collecting Event Logs and other WMI data remotely, you will be able to easily collect and forward other data such as DNS, DHCP, Windows Update, and application logs.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2012 07:17:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WMI-How-many-remote-Windows-can-a-Splunk-WMI-input-support/m-p/37893#M6963</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-04-27T07:17:24Z</dc:date>
    </item>
  </channel>
</rss>

