All Apps and Add-ons

How to collect and index data from Windows servers after installing the Splunk Add-on for Microsoft Windows?

roopeshetty
Path Finder

Hi

We have installed Splunk Add-on for Microsoft Windows on our Splunk 6.3.3 by downloading the splunk-add-on-for-microsoft-windows_483.tgz file and installing it from Install app from file tab. However, we do not know what is the next step to get the events from a Windows server. We have already added some servers using Settings>Data inputs>Remote performance monitoring and we are able to get the events through WMI.

Can someone please advise us how to get the events from a server through Splunk Add-on for Microsoft Windows?

Regards

0 Karma

dstaulcu
Builder

The original version of Splunk_TA_Windows can be found in the etc\apps folder of the search head you installed it on.

Copy the etc\apps\Splunk_TA_Windows folder to some other location, personalize it to meet your input collection requirements, and then distribute that folder to the etc\apps folder among universal forwarders.

Here are instructions for personalizing a version of Splunk_TA_Windows

http://docs.splunk.com/Documentation/WindowsAddOn/4.8.3/User/InstalltheSplunkAdd-onforWindows

http://docs.splunk.com/Documentation/WindowsAddOn/4.8.3/User/Configuration

0 Karma

roopeshetty
Path Finder

So without the agent universal forwarder we can not use Splunk Add-on for Microsoft Windows plugin?

0 Karma

dstaulcu
Builder

You would miss out on >60% of possible source types and also take a hit on reliability and efficiency of feeds without using some form of forwarder on the host.

0 Karma

roopeshetty
Path Finder

Hi, Thats fine, but where to configure it in splunk server. Actually we are looking for physical memory (RAM) utilisation events from a windows server but we dont want to install the agent universal forwarder in that server. So is there any option so that we can get physical memory (RAM) utilisation events from that server without installing the agent universal forwarder in that server?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...