<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Splunk search client machines System log that has Event ID 7? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58068#M179993</link>
    <description>&lt;P&gt;Thanks, do you know of a tool that can help us?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2013 15:27:03 GMT</pubDate>
    <dc:creator>tomwahab</dc:creator>
    <dc:date>2013-06-10T15:27:03Z</dc:date>
    <item>
      <title>Can Splunk search client machines System log that has Event ID 7?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58066#M179991</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
Can Splunk search client machines System log that has Event ID 7?  We need to scan and retrieve hostnames that have this event ID which is a disk error&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2013 23:26:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58066#M179991</guid>
      <dc:creator>tomwahab</dc:creator>
      <dc:date>2013-06-07T23:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk search client machines System log that has Event ID 7?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58067#M179992</link>
      <description>&lt;P&gt;Splunk will not scan your network. If you install a forwarder on each machine (or some other agent capable of retrieving logs), you can send them to a Splunk indexer. There you can search through the logs, looking for your events.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2013 06:51:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58067#M179992</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-06-08T06:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk search client machines System log that has Event ID 7?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58068#M179993</link>
      <description>&lt;P&gt;Thanks, do you know of a tool that can help us?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2013 15:27:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58068#M179993</guid>
      <dc:creator>tomwahab</dc:creator>
      <dc:date>2013-06-10T15:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk search client machines System log that has Event ID 7?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58069#M179994</link>
      <description>&lt;P&gt;install a universal forwarder?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2013 15:41:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58069#M179994</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2013-06-10T15:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk search client machines System log that has Event ID 7?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58070#M179995</link>
      <description>&lt;P&gt;thanks, so we would have to install splunk universal forwarder on all our client machines.  How big is the software package for the forwarder and is it an easy deployment?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2013 16:06:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58070#M179995</guid>
      <dc:creator>tomwahab</dc:creator>
      <dc:date>2013-06-10T16:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk search client machines System log that has Event ID 7?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58071#M179996</link>
      <description>&lt;P&gt;You can script the forwarder install with any normal config management tools you have already that can deploy msi installer packages. Then just use a splunk deployment server to control the log collection configuration. Typically done by using the Splunk for Windows TA.  However if you have a lot of hosts you may have to consider how big your license is.  An alternative would be use a free windows eventlog to syslog tool like Snare for Windows.  It can be set to filter what events it sends.  Then pickup, index and search those received syslogs.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2013 02:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-search-client-machines-System-log-that-has-Event-ID-7/m-p/58071#M179996</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2013-06-15T02:29:33Z</dc:date>
    </item>
  </channel>
</rss>

