<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: server monitoring in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/server-monitoring/m-p/494791#M1968</link>
    <description>&lt;P&gt;Hi @punithjigali,&lt;BR /&gt;
if you have the ITSI, there are many Use Cases already available for Windows OS.&lt;/P&gt;

&lt;P&gt;If you haven't the ITSI, I hint to install the Splunk App for Windows Infrastructure that contains many dashboards.&lt;/P&gt;

&lt;P&gt;In addition, it's possible to implement using Windows logs:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;login, logout and logfails,&lt;/LI&gt;
&lt;LI&gt;extract server configurations,&lt;/LI&gt;
&lt;LI&gt;installed applications,&lt;/LI&gt;
&lt;LI&gt;servers status,&lt;/LI&gt;
&lt;LI&gt;excessive use of resources (CPUs, RAM, HDs, etc...)&lt;/LI&gt;
&lt;LI&gt;etc...&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Your question should be send to a Windows administrator not to a Splunk developer: ask to a Windows administrator what he needs and realize this with Splunk.&lt;BR /&gt;
In addition you could ask to a Security Manager what are the security Use Cases he needs: brute force, non active users, etc...&lt;/P&gt;

&lt;P&gt;At the end, see in apps.splunk.com if there are Apps that are interesting for you and start from them.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 07 May 2020 12:32:37 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-05-07T12:32:37Z</dc:date>
    <item>
      <title>server monitoring</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/server-monitoring/m-p/494790#M1967</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;I have installed UF and add on for windows and getting server data to my splunk instance.....&lt;/P&gt;
&lt;P&gt;are there any use cases on monitoring and forecast predicting using MLTK for this data...??&lt;/P&gt;
&lt;P&gt;this is the server data..... &lt;BR /&gt;and the data is generated by add on windows....&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 00:08:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/server-monitoring/m-p/494790#M1967</guid>
      <dc:creator>punithjigali</dc:creator>
      <dc:date>2020-06-07T00:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: server monitoring</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/server-monitoring/m-p/494791#M1968</link>
      <description>&lt;P&gt;Hi @punithjigali,&lt;BR /&gt;
if you have the ITSI, there are many Use Cases already available for Windows OS.&lt;/P&gt;

&lt;P&gt;If you haven't the ITSI, I hint to install the Splunk App for Windows Infrastructure that contains many dashboards.&lt;/P&gt;

&lt;P&gt;In addition, it's possible to implement using Windows logs:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;login, logout and logfails,&lt;/LI&gt;
&lt;LI&gt;extract server configurations,&lt;/LI&gt;
&lt;LI&gt;installed applications,&lt;/LI&gt;
&lt;LI&gt;servers status,&lt;/LI&gt;
&lt;LI&gt;excessive use of resources (CPUs, RAM, HDs, etc...)&lt;/LI&gt;
&lt;LI&gt;etc...&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Your question should be send to a Windows administrator not to a Splunk developer: ask to a Windows administrator what he needs and realize this with Splunk.&lt;BR /&gt;
In addition you could ask to a Security Manager what are the security Use Cases he needs: brute force, non active users, etc...&lt;/P&gt;

&lt;P&gt;At the end, see in apps.splunk.com if there are Apps that are interesting for you and start from them.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 12:32:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/server-monitoring/m-p/494791#M1968</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-05-07T12:32:37Z</dc:date>
    </item>
  </channel>
</rss>

