All Apps and Add-ons

How to collect and index data from Windows servers after installing the Splunk Add-on for Microsoft Windows?

roopeshetty
Path Finder

Hi

We have installed Splunk Add-on for Microsoft Windows on our Splunk 6.3.3 by downloading the splunk-add-on-for-microsoft-windows_483.tgz file and installing it from Install app from file tab. However, we do not know what is the next step to get the events from a Windows server. We have already added some servers using Settings>Data inputs>Remote performance monitoring and we are able to get the events through WMI.

Can someone please advise us how to get the events from a server through Splunk Add-on for Microsoft Windows?

Regards

0 Karma

dstaulcu
Builder

The original version of Splunk_TA_Windows can be found in the etc\apps folder of the search head you installed it on.

Copy the etc\apps\Splunk_TA_Windows folder to some other location, personalize it to meet your input collection requirements, and then distribute that folder to the etc\apps folder among universal forwarders.

Here are instructions for personalizing a version of Splunk_TA_Windows

http://docs.splunk.com/Documentation/WindowsAddOn/4.8.3/User/InstalltheSplunkAdd-onforWindows

http://docs.splunk.com/Documentation/WindowsAddOn/4.8.3/User/Configuration

0 Karma

roopeshetty
Path Finder

So without the agent universal forwarder we can not use Splunk Add-on for Microsoft Windows plugin?

0 Karma

dstaulcu
Builder

You would miss out on >60% of possible source types and also take a hit on reliability and efficiency of feeds without using some form of forwarder on the host.

0 Karma

roopeshetty
Path Finder

Hi, Thats fine, but where to configure it in splunk server. Actually we are looking for physical memory (RAM) utilisation events from a windows server but we dont want to install the agent universal forwarder in that server. So is there any option so that we can get physical memory (RAM) utilisation events from that server without installing the agent universal forwarder in that server?

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...