All Apps and Add-ons

Is the Splunk Add-on for Microsoft Windows necessary on a Windows system?

ritsma
Engager

We currently run Splunk Enterprise Version 6.4.2 on Linux.

We are in the process of installing a light forwarder on a Windows system.

While looking at existing configurations we have found different setups, some with the Splunk Add-on for Microsoft Windows and some
without. The question is going forward, what additional functionality would we get from the add-on since the base forwarder
without the add-on provides us access to the Windows logs?

Thanks...Rob

0 Karma

woodcock
Esteemed Legend

The method of accessing Windows through the logs or WMI is far more error-prone than using the TA. I always use the TA on Windows forwarders.

gcusello
SplunkTrust
SplunkTrust

Hi ritsma,
I always disable windows logs functionalities in the forwarders installation and I deploy Splunk_TA_Windows using a Deployment Server so I can manageconfigurations.

Bye.
Giuseppe

Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...