<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use a heavy forwader to pull through WMI and send to Splunk cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487166#M83436</link>
    <description>&lt;P&gt;If you need to go via the WMI route, use this docs to help you get started&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Data/MonitorWMIdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Data/MonitorWMIdata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can do this with just the UF. &lt;BR /&gt;
So, if you've the capability to install UF's (preferred method) then get the Splunk_TA_Windows&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/742/" target="_blank"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Docs for setting it up the app&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/MSApp/2.0.0/MSInfra/DownloadandconfiguretheSplunkAdd-onforWindowsversion6.0.0orlater" target="_blank"&gt;https://docs.splunk.com/Documentation/MSApp/2.0.0/MSInfra/DownloadandconfiguretheSplunkAdd-onforWindowsversion6.0.0orlater&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;On your cloud instance you'll have the Universal Forwarder app, which will provide you the config to send data to the cloud.&lt;/P&gt;

&lt;P&gt;You &lt;EM&gt;might&lt;/EM&gt; need to raise a Splunk support ticket to have the app deployed on Splunk Cloud, so the data can be parsed correctly.&lt;/P&gt;

&lt;P&gt;Now, if you're planning to collect windows data at scale, it would also be ideal to look at setting up a deployment server and pushing out the configurations via that. This will help with centralised management.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:29:27 GMT</pubDate>
    <dc:creator>anmolpatel</dc:creator>
    <dc:date>2020-09-30T04:29:27Z</dc:date>
    <item>
      <title>Use a heavy forwader to pull through WMI and send to Splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487163#M83433</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;In this particular situation we'd like to use a heavy forwader to be able to pull Windows event logs from windows devices in datacenter though WMI on prem and send to Splunk cloud. Is that possible?&lt;/P&gt;

&lt;P&gt;Thanks in advance, &lt;BR /&gt;
Erik&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 15:49:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487163#M83433</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2020-03-04T15:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Use a heavy forwader to pull through WMI and send to Splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487164#M83434</link>
      <description>&lt;P&gt;Yes, it is possible, but you don't need a heavy forwarder to do that.  A universal forwarder will work just fine.&lt;/P&gt;

&lt;P&gt;Once you install the forwarder of choice, configure an inputs.conf file to pull the desired events.  Then download the "Universal Forwarder" app from your Splunk Cloud account and install it on the forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 18:31:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487164#M83434</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-04T18:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Use a heavy forwader to pull through WMI and send to Splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487165#M83435</link>
      <description>&lt;P&gt;Thank you for your answer. So in order to pull the logs from all these Windows devices through WMI, one needs only a Universal Forwarder on one Windows device and send it to the Splunk cloud right?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 19:52:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487165#M83435</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2020-03-04T19:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Use a heavy forwader to pull through WMI and send to Splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487166#M83436</link>
      <description>&lt;P&gt;If you need to go via the WMI route, use this docs to help you get started&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Data/MonitorWMIdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Data/MonitorWMIdata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can do this with just the UF. &lt;BR /&gt;
So, if you've the capability to install UF's (preferred method) then get the Splunk_TA_Windows&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/742/" target="_blank"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Docs for setting it up the app&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/MSApp/2.0.0/MSInfra/DownloadandconfiguretheSplunkAdd-onforWindowsversion6.0.0orlater" target="_blank"&gt;https://docs.splunk.com/Documentation/MSApp/2.0.0/MSInfra/DownloadandconfiguretheSplunkAdd-onforWindowsversion6.0.0orlater&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;On your cloud instance you'll have the Universal Forwarder app, which will provide you the config to send data to the cloud.&lt;/P&gt;

&lt;P&gt;You &lt;EM&gt;might&lt;/EM&gt; need to raise a Splunk support ticket to have the app deployed on Splunk Cloud, so the data can be parsed correctly.&lt;/P&gt;

&lt;P&gt;Now, if you're planning to collect windows data at scale, it would also be ideal to look at setting up a deployment server and pushing out the configurations via that. This will help with centralised management.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:29:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487166#M83436</guid>
      <dc:creator>anmolpatel</dc:creator>
      <dc:date>2020-09-30T04:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Use a heavy forwader to pull through WMI and send to Splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487167#M83437</link>
      <description>&lt;P&gt;Yes. However, WMI uses more resources than running a local UF on each Windows device.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 13:58:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Use-a-heavy-forwader-to-pull-through-WMI-and-send-to-Splunk/m-p/487167#M83437</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-05T13:58:35Z</dc:date>
    </item>
  </channel>
</rss>

