All Apps and Add-ons

Splunk cannot find "admin/win-event-log-collections".

mikeely
Path Finder

New install of Splunk on 64-bit RHEL, configured universal forwarder on 32-bit win2k3 machine and see some events coming through so I know at some level it's working. Problem is, when I go to look at perf graphs they all say "no data found" and the associated WMI Management link leads to the 404 error given in the title here. I can also get the same 404 error when I click the "Get more data into your Splunk: Get remote event logs via WMI." link as well.

Looks to me like the Windows app is somehow broken on my install. Thoughts?

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You can only collect data via WMI from a Windows version of Splunk, and then forward those to the Linux indexer. The UF (the one you have on Windows) unfortunately does not have a GUI for configuring WMI collection, but it can in fact do the collection as long as the correct configuration files are created and applied.

View solution in original post

mikeely
Path Finder

So would this be a job for deployment server? I'm guessing I'd use a full-fledged windows forwarder just to create the configuration properly and then send that out to the other windows machines through deployment, but there are probably a few complications to this that aren't obvious to me.

0 Karma

mikelanghorst
Motivator

A deployment server would make the process of getting the configs to the individual servers easier.

You'll be best off by using a single windows host to configure manually first: http://www.splunk.com/base/Documentation/4.2.2/Data/MonitorWMIdata create a directory under that forwarders etc/apps. Then once you have it working on that host copy the directory you have to a deployment server then push it out from there.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can only collect data via WMI from a Windows version of Splunk, and then forward those to the Linux indexer. The UF (the one you have on Windows) unfortunately does not have a GUI for configuring WMI collection, but it can in fact do the collection as long as the correct configuration files are created and applied.

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...