<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I send Windows data to Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-data-to-Splunk/m-p/93934#M97419</link>
    <description>&lt;P&gt;Since this post is old, I'll add to the answer some updated links that could help:&lt;BR /&gt;
* &lt;A href="https://answers.splunk.com/answers/743633/how-do-i-get-basic-performance-data-for-my-windows.html"&gt;How do I get basic performance data for my Windows systems?&lt;/A&gt;&lt;BR /&gt;
* &lt;A href="https://answers.splunk.com/answers/744435/what-are-the-best-practices-for-installing-splunk.html"&gt;What are the best practices for installing Splunk on Windows endpoints?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You may see more within the &lt;A href="https://answers.splunk.com/topics/validated_best-practice.html"&gt;validated_best-practice&lt;/A&gt; tag and within the official &lt;A href="https://docs.splunk.com"&gt;product documentation&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2019 12:44:34 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2019-05-02T12:44:34Z</dc:date>
    <item>
      <title>How do I send Windows data to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-data-to-Splunk/m-p/93932#M97417</link>
      <description>&lt;P&gt;How do I send Windows data to Splunk?  I have the app installed but can't figure out how to pull the data from the windows boxes...&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2010 10:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-data-to-Splunk/m-p/93932#M97417</guid>
      <dc:creator>cgautreaux</dc:creator>
      <dc:date>2010-11-24T10:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send Windows data to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-data-to-Splunk/m-p/93933#M97418</link>
      <description>&lt;P&gt;Assuming that your environment is that you have a server with Splunk installed and other Windows machines connected on the network for which you want to collect data, you will want to deploy a forwarder on the Windows machines.&lt;/P&gt;

&lt;P&gt;You can follow these steps to enable receiving and forwarding for getting data in to Splunk from the Windows machines:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;On your Splunk server, go to "Manager&amp;gt;&amp;gt;Forwarding and receiving&amp;gt;&amp;gt;Configure receiving"&lt;/LI&gt;
&lt;LI&gt;Click on "New"&lt;/LI&gt;
&lt;LI&gt;Enter an unused port number on which you would like Splunk to listen on in order to receive Splunk data. (e.g. 9000).&lt;/LI&gt;
&lt;LI&gt;Click on "Save"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;On your Windows machines do the following:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Install Splunk on the Windows machines and configure the data inputs that you want to collect. &lt;/LI&gt;
&lt;LI&gt;Go to "Manager&amp;gt;&amp;gt;Forwarding and receiving&amp;gt;&amp;gt;Configure forwarding"&lt;/LI&gt;
&lt;LI&gt;Click on "New"&lt;/LI&gt;
&lt;LI&gt;Enter the SPlunk hostname or IP and the port number as above. (e.g. Splunkserver:9000 or 192.168.1.100:9000)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;You have now set up a forwarder on that Windows machine that will collect data and can be configured via the web interface. You can disable the Web UI by making the Splunk instance on the Windows machine a Light Weight Forwarder. This can be done by going to "Manager&amp;gt;&amp;gt;Forwarding and receiving&amp;gt;&amp;gt;Enable light forwarding" You will see a warning message that the web UI will be disabled and that Splunk will only be accessible via the CLI interface (command line shell on Windows) for further configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2010 18:21:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-data-to-Splunk/m-p/93933#M97418</guid>
      <dc:creator>Rob</dc:creator>
      <dc:date>2010-11-24T18:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send Windows data to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-data-to-Splunk/m-p/93934#M97419</link>
      <description>&lt;P&gt;Since this post is old, I'll add to the answer some updated links that could help:&lt;BR /&gt;
* &lt;A href="https://answers.splunk.com/answers/743633/how-do-i-get-basic-performance-data-for-my-windows.html"&gt;How do I get basic performance data for my Windows systems?&lt;/A&gt;&lt;BR /&gt;
* &lt;A href="https://answers.splunk.com/answers/744435/what-are-the-best-practices-for-installing-splunk.html"&gt;What are the best practices for installing Splunk on Windows endpoints?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You may see more within the &lt;A href="https://answers.splunk.com/topics/validated_best-practice.html"&gt;validated_best-practice&lt;/A&gt; tag and within the official &lt;A href="https://docs.splunk.com"&gt;product documentation&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 12:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-Windows-data-to-Splunk/m-p/93934#M97419</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-05-02T12:44:34Z</dc:date>
    </item>
  </channel>
</rss>

