<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there a best practice guide for Splunk and Windows Event Collectors? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-best-practice-guide-for-Splunk-and-Windows-Event/m-p/415493#M73464</link>
    <description>&lt;P&gt;Does anyone have a guide for load balancing among Windows Event Collectors?&lt;/P&gt;

&lt;P&gt;We have about 8 Windows Event Collector Servers.  &lt;/P&gt;

&lt;P&gt;We want to know if there is a &lt;STRONG&gt;best practice&lt;/STRONG&gt; guide to get this set up correctly in Splunk, or any other SIEM.&lt;/P&gt;

&lt;P&gt;We appear to be experiencing &lt;STRONG&gt;latency&lt;/STRONG&gt; from the time the event is transmitted from the UF -----&amp;gt; HF.........&amp;gt;IDX.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2019 13:59:36 GMT</pubDate>
    <dc:creator>itrimble1</dc:creator>
    <dc:date>2019-06-07T13:59:36Z</dc:date>
    <item>
      <title>Is there a best practice guide for Splunk and Windows Event Collectors?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-best-practice-guide-for-Splunk-and-Windows-Event/m-p/415493#M73464</link>
      <description>&lt;P&gt;Does anyone have a guide for load balancing among Windows Event Collectors?&lt;/P&gt;

&lt;P&gt;We have about 8 Windows Event Collector Servers.  &lt;/P&gt;

&lt;P&gt;We want to know if there is a &lt;STRONG&gt;best practice&lt;/STRONG&gt; guide to get this set up correctly in Splunk, or any other SIEM.&lt;/P&gt;

&lt;P&gt;We appear to be experiencing &lt;STRONG&gt;latency&lt;/STRONG&gt; from the time the event is transmitted from the UF -----&amp;gt; HF.........&amp;gt;IDX.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 13:59:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-best-practice-guide-for-Splunk-and-Windows-Event/m-p/415493#M73464</guid>
      <dc:creator>itrimble1</dc:creator>
      <dc:date>2019-06-07T13:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a best practice guide for Splunk and Windows Event Collectors?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-best-practice-guide-for-Splunk-and-Windows-Event/m-p/415494#M73465</link>
      <description>&lt;P&gt;I thought I'd answer this post, since I've learned a lot in between the original question and now.  &lt;STRONG&gt;These resources really helped me out&lt;/STRONG&gt;.  I hope they can do the same for you.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://blogs.technet.microsoft.com/jepayne/2015/11/23/monitoring-what-matters-windows-event-forwarding-for-everyone-even-if-you-already-have-a-siem/"&gt;Monitoring What Matters&lt;/A&gt;  - Jessica Payne (Microsoft)&lt;BR /&gt;
&lt;A href="https://www.splunk.com/blog/2017/08/07/peeping-through-windows-logs.html"&gt;Peeping Through WIndows&lt;/A&gt; (Logs)  - Hunting With Splunk - Part 5&lt;BR /&gt;
&lt;A href="https://www.ultimatewindowssecurity.com/webinars/register.aspx?id=1433"&gt;Integrating Splunk with native Windows Event Collection&lt;/A&gt; - Great Webinar from Ultimate Windows Security&lt;BR /&gt;
&lt;A href="https://www.batchworks.de/why-using-xml-event-logs-sucks-using-splunk/"&gt;To XML or Classic Format&lt;/A&gt;  - Conclusion is that XML collection is slower than classic rendering&lt;BR /&gt;
&lt;A href="https://github.com/palantir/windows-event-forwarding"&gt;Windows Event Forwarding Guidance&lt;/A&gt;  - Guide to help setting up central Windows Logging through a collector&lt;BR /&gt;
&lt;A href="https://blogs.technet.microsoft.com/russellt/2017/05/09/project-sauron-introduction/"&gt;Project Sauron&lt;/A&gt; - Centralized Storage of Windows Events (Microsoft)&lt;BR /&gt;
&lt;A href="https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wecutil"&gt;Create and Manage Subscriptions with PowerShell&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wecutil"&gt;Best Practice for Configuring EventLog Forwarding&lt;/A&gt;  - specifically Server 2012R2, Server 2016&lt;BR /&gt;
&lt;A href="https://www.hurricanelabs.com/splunk-tutorials/windows-event-log-filtering-design-in-splunk#"&gt;Blacklists and Whitelist Tuning&lt;/A&gt; - Hurricane Labs  - Great guide to save on licensing&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 17:11:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-best-practice-guide-for-Splunk-and-Windows-Event/m-p/415494#M73465</guid>
      <dc:creator>itrimble1</dc:creator>
      <dc:date>2019-10-08T17:11:48Z</dc:date>
    </item>
  </channel>
</rss>

