We have installed Splunk Add-on for Microsoft Windows on our Splunk 6.3.3 by downloading the splunk-add-on-for-microsoft-windows_483.tgz file and installing it from Install app from file tab. However, we do not know what is the next step to get the events from a Windows server. We have already added some servers using Settings>Data inputs>Remote performance monitoring and we are able to get the events through WMI.
Can someone please advise us how to get the events from a server through Splunk Add-on for Microsoft Windows?
The original version of SplunkTAWindows can be found in the etc\apps folder of the search head you installed it on.
Copy the etc\apps\SplunkTAWindows folder to some other location, personalize it to meet your input collection requirements, and then distribute that folder to the etc\apps folder among universal forwarders.
Here are instructions for personalizing a version of SplunkTAWindows
So without the agent universal forwarder we can not use Splunk Add-on for Microsoft Windows plugin?
You would miss out on >60% of possible source types and also take a hit on reliability and efficiency of feeds without using some form of forwarder on the host.
Hi, Thats fine, but where to configure it in splunk server. Actually we are looking for physical memory (RAM) utilisation events from a windows server but we dont want to install the agent universal forwarder in that server. So is there any option so that we can get physical memory (RAM) utilisation events from that server without installing the agent universal forwarder in that server?