All Apps and Add-ons

Splunk for Windows Technology add-on VS. Splunk for Windows

treinke
Builder

What are the benefits of Splunk for Windows technology add-on over Splunk for Windows?

There are no answer without questions
1 Solution

araitz
Splunk Employee
Splunk Employee

Some customers asked us for Windows knowledge (eventtypes, fields, lookups, etc) and input (WinEvtLog, WMI, etc) packaged separately from the Splunk Web UI aspects. Often, this request was in order to facilitate use on forwarders or when the primary use case for Windows data is to correlate with other data sources in an app other than Splunk for Windows.

In terms of the knowledge layer, the Windows technology add-on does have a few benefits compared to the Splunk for Windows app. Besides more in depth descriptions and the addition of event code lookups, a key thing to note is that the Windows technology add-on is Common Information Model compliant, which facilitates use with CIM-compliant solutions such as Splunk Enterprise Security Suite and Splunk for PCI Compliance.

View solution in original post

araitz
Splunk Employee
Splunk Employee

Some customers asked us for Windows knowledge (eventtypes, fields, lookups, etc) and input (WinEvtLog, WMI, etc) packaged separately from the Splunk Web UI aspects. Often, this request was in order to facilitate use on forwarders or when the primary use case for Windows data is to correlate with other data sources in an app other than Splunk for Windows.

In terms of the knowledge layer, the Windows technology add-on does have a few benefits compared to the Splunk for Windows app. Besides more in depth descriptions and the addition of event code lookups, a key thing to note is that the Windows technology add-on is Common Information Model compliant, which facilitates use with CIM-compliant solutions such as Splunk Enterprise Security Suite and Splunk for PCI Compliance.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...