All Apps and Add-ons

TA_Windows and Windows Infrastructure - Printer inputs?

Wallen
Explorer

According to the Splunk App for Windows infrastructure docs, there should be a printer monitoring input available int the Splunk Add-On for Microsoft Windows. I have been looking all over the config files for the Technology Addon for Windows on my servers that have the app installed with within the universal forwarders, and I can't find any inputs to enable for print job monitoring.

Now, I could simply turn on the input on the Universal Forwarder's config, or add it to the TA's App config, however, the sourcetype expected by the Infrastructure App on my Indexer is "WinPrintMon", and not "WinEventLog:Microsoft-Windows-PrintService/Operational".

If there is an exisiting input on the TA to turn on, where is it?
If not, and I manually have to add it... do I simply force the sourcetype as "WinPrintMon" on the inputs.conf, or do I need to do a bunch of hullaballoo with props and transforms, too?

0 Karma

ppablo
Retired

Hi @Wallen

Did the detection monitoring in the following documentation find print monitoring in your environment when you initially installed?
http://docs.splunk.com/Documentation/MSApp/1.0.2/MSInfra/ConfiguretheSplunkAppforWindowsInfrastructu...

There should also be a Setup Menu to enable inputs:
http://docs.splunk.com/Documentation/MSApp/1.0.2/MSInfra/Dashboardreference-Windows#Get_Data_In

0 Karma

ppablo
Retired

What version of Splunk is your environment running? For Splunk 6.1.2, both full instances of Splunk Enterprise and universal forwarders for Windows support local collection of printer subsystem information. It can be configured using Splunk web or inputs.conf. The following documentation shows the monitoring configuration stanzas in inputs.conf and the WinPrintMon sourcetype that your indexer is expecting:
http://docs.splunk.com/Documentation/Splunk/6.1.2/Data/MonitorWindowsprinterinformation

0 Karma

Wallen
Explorer

It's not on the Splunk App for Windows Infrastructure side... it's on the Server's Universal forwarder / Splunk Technology Addon for Windows side of things:

http://docs.splunk.com/Documentation/MSApp/latest/MSInfra/Configuretheadd-ons

Specifically:
Splunk Add-on for Windows (Splunk_TA_Windows) - On Splunk Apps. - Windows statistics (Event logs, Registry/network/host/print monitoring)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...