All Apps and Add-ons
Highlighted

How to collect and index data from Windows servers after installing the Splunk Add-on for Microsoft Windows?

New Member

Hi

We have installed Splunk Add-on for Microsoft Windows on our Splunk 6.3.3 by downloading the splunk-add-on-for-microsoft-windows_483.tgz file and installing it from Install app from file tab. However, we do not know what is the next step to get the events from a Windows server. We have already added some servers using Settings>Data inputs>Remote performance monitoring and we are able to get the events through WMI.

Can someone please advise us how to get the events from a server through Splunk Add-on for Microsoft Windows?

Regards

0 Karma
Highlighted

Re: How to collect and index data from Windows servers after installing the Splunk Add-on for Microsoft Windows?

Builder

The original version of SplunkTAWindows can be found in the etc\apps folder of the search head you installed it on.

Copy the etc\apps\SplunkTAWindows folder to some other location, personalize it to meet your input collection requirements, and then distribute that folder to the etc\apps folder among universal forwarders.

Here are instructions for personalizing a version of SplunkTAWindows

http://docs.splunk.com/Documentation/WindowsAddOn/4.8.3/User/InstalltheSplunkAdd-onforWindows

http://docs.splunk.com/Documentation/WindowsAddOn/4.8.3/User/Configuration

0 Karma
Highlighted

Re: How to collect and index data from Windows servers after installing the Splunk Add-on for Microsoft Windows?

New Member

So without the agent universal forwarder we can not use Splunk Add-on for Microsoft Windows plugin?

0 Karma
Highlighted

Re: How to collect and index data from Windows servers after installing the Splunk Add-on for Microsoft Windows?

Builder

You would miss out on >60% of possible source types and also take a hit on reliability and efficiency of feeds without using some form of forwarder on the host.

0 Karma
Highlighted

Re: How to collect and index data from Windows servers after installing the Splunk Add-on for Microsoft Windows?

New Member

Hi, Thats fine, but where to configure it in splunk server. Actually we are looking for physical memory (RAM) utilisation events from a windows server but we dont want to install the agent universal forwarder in that server. So is there any option so that we can get physical memory (RAM) utilisation events from that server without installing the agent universal forwarder in that server?

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.