<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agent vs Agentless event gathering on Windows in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Agent-vs-Agentless-event-gathering-on-Windows/m-p/12480#M932</link>
    <description>&lt;P&gt;there's also some good info in the official docs here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/ConsiderationsfordecidinghowtomonitorWindowsdata" rel="nofollow"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/ConsiderationsfordecidinghowtomonitorWindowsdata&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2010 00:55:08 GMT</pubDate>
    <dc:creator>piebob</dc:creator>
    <dc:date>2010-04-29T00:55:08Z</dc:date>
    <item>
      <title>Agent vs Agentless event gathering on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Agent-vs-Agentless-event-gathering-on-Windows/m-p/12478#M930</link>
      <description>&lt;P&gt;Regarding agent vs agentless data / event gatering, WMI (agentless) seems easier to setup from within Splunk to pull in the data from remote Windows servers. So why would someone deploy Splunk as a Forwarder (agent) on their Windows servers to push the data in?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2010 00:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Agent-vs-Agentless-event-gathering-on-Windows/m-p/12478#M930</guid>
      <dc:creator>maverick</dc:creator>
      <dc:date>2010-04-29T00:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Agent vs Agentless event gathering on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Agent-vs-Agentless-event-gathering-on-Windows/m-p/12479#M931</link>
      <description>&lt;P&gt;Please review this topic in our community wiki for more detail regarding this question.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/wiki/Deploy:SnareVwmiVforwarding" rel="nofollow"&gt;http://www.splunk.com/wiki/Deploy:SnareVwmiVforwarding&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also,&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;WMI does not pull data via SSL, but Splunk Forward can push data over SSL&lt;/LI&gt;
&lt;LI&gt;pulling data with WMI may produce gaps in the data, if/when service is restarted&lt;/LI&gt;
&lt;LI&gt;Splunk Forwarder can monitor and push up non-Windows data as well (i.e. IIS events, MSSQL, DIR listings every hour, etc.)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 29 Apr 2010 00:51:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Agent-vs-Agentless-event-gathering-on-Windows/m-p/12479#M931</guid>
      <dc:creator>maverick</dc:creator>
      <dc:date>2010-04-29T00:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Agent vs Agentless event gathering on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Agent-vs-Agentless-event-gathering-on-Windows/m-p/12480#M932</link>
      <description>&lt;P&gt;there's also some good info in the official docs here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/ConsiderationsfordecidinghowtomonitorWindowsdata" rel="nofollow"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/ConsiderationsfordecidinghowtomonitorWindowsdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2010 00:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Agent-vs-Agentless-event-gathering-on-Windows/m-p/12480#M932</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2010-04-29T00:55:08Z</dc:date>
    </item>
  </channel>
</rss>

