All Apps and Add-ons

Best Practice for Using Splunk_TA_windows on Workstations and Servers

dstuder
Communicator

I'm upgrading the Splunk_TA_windows to the newest version in our environment. We are coming from an old 5.x version. Now that the Windows TA, Active Directory TA, and the DNS TA have all been consolidated into one TA, I've got some questions for how to best deploy this.

I've looked at the local inputs.conf files for all three of the legacy TAs and consolidated them into a local inputs.conf file for the new TA. I've deployed it to one machine using the deployment server and have immediately discovered an issue. I figured the AD and DNS logs would not be present on a Workstation PC so those pieces would not run, however, that's not the case. Some the AD powershell inputs are running on my laptop, which is not what I want. So, I'm figuring I need to find a way to split out the local inputs.conf file by machine type (workstation/server/domain controller/DNS server).

I'm thinking maybe I need to deploy the Splunk_TA_windows to all our windows machines as is ... no local inputs.conf. And then maybe create small apps to turn on certain features of the TA per machine type. Is that the right way to do this? Would that even work? I'm thinking there might be issues with the scripted inputs as the script files would live in another app. Anyway, I'm just not sure what the best way to handle this is. Any help would be much appreciated.

Labels (1)
1 Solution

isoutamo
SplunkTrust
SplunkTrust
You have figured out good way to handle this. Deploy the original TA without (or containing only general inputs for all node types + possible internals) and then create suitable amount of additional TAs just for node type specific inputs.

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

I think deploying base Splunk_TA_windows (all inputs disabled) and then deploying machine type specific apps with just inputs.conf with related inputs enable would be the way to go. I think scripted inputs will work too, if not, you may have to specify relative path for those inputs (if needed).

isoutamo
SplunkTrust
SplunkTrust
You have figured out good way to handle this. Deploy the original TA without (or containing only general inputs for all node types + possible internals) and then create suitable amount of additional TAs just for node type specific inputs.
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...