All Apps and Add-ons

Splunk Add-on for Microsoft Windows: Unable to get output

chanduira
Explorer

Hi,
I want some hardware informations remotely on the list of Windows servers. I have downloaded the Windows Add-on, created the inputs.conf in Splunk_TA_Windows, still unable to get the output, neither an error, seems no instance of this Add-On is found on the executing of Forwarder on the testing client?
alt text

This is the link what i was following for this execution:
https://www.splunk.com/blog/2013/10/09/windows-host-monitoring-in-splunk-6.html

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi chanduira,
Where do you installed Splunk_TA_Windows on Indexer or Forwarder?
This TA can be used only on Forwarder.

Did you tested the connection between forwarder and indexer?
Did Indexer receive _internal logs (index=_internal host=your_host)

Bye.
Giuseppe

0 Karma

chanduira
Explorer

Hi Giuseppe,

I have installed Splunk_TA_Windows on the forwarder.
Connection is open at port 9997 between Forwarder and Indexer.
Indexer is receiving my other app logs from the same forwarder except Splunk_TA_Windows.

Thanks Giuseppe for your response.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...