All Apps and Add-ons

Splunk for Windows Technology add-on VS. Splunk for Windows

treinke
Builder

What are the benefits of Splunk for Windows technology add-on over Splunk for Windows?

There are no answer without questions
1 Solution

araitz
Splunk Employee
Splunk Employee

Some customers asked us for Windows knowledge (eventtypes, fields, lookups, etc) and input (WinEvtLog, WMI, etc) packaged separately from the Splunk Web UI aspects. Often, this request was in order to facilitate use on forwarders or when the primary use case for Windows data is to correlate with other data sources in an app other than Splunk for Windows.

In terms of the knowledge layer, the Windows technology add-on does have a few benefits compared to the Splunk for Windows app. Besides more in depth descriptions and the addition of event code lookups, a key thing to note is that the Windows technology add-on is Common Information Model compliant, which facilitates use with CIM-compliant solutions such as Splunk Enterprise Security Suite and Splunk for PCI Compliance.

View solution in original post

araitz
Splunk Employee
Splunk Employee

Some customers asked us for Windows knowledge (eventtypes, fields, lookups, etc) and input (WinEvtLog, WMI, etc) packaged separately from the Splunk Web UI aspects. Often, this request was in order to facilitate use on forwarders or when the primary use case for Windows data is to correlate with other data sources in an app other than Splunk for Windows.

In terms of the knowledge layer, the Windows technology add-on does have a few benefits compared to the Splunk for Windows app. Besides more in depth descriptions and the addition of event code lookups, a key thing to note is that the Windows technology add-on is Common Information Model compliant, which facilitates use with CIM-compliant solutions such as Splunk Enterprise Security Suite and Splunk for PCI Compliance.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...