All Apps and Add-ons

What does the Splunk Add-on for Windows do that the Universal Forwarder alone does not?

bbeavise2g
Explorer

I'm pretty new to Splunk and I have been looking into Forwarder Deployment for central administration. My confusion is that some of our systems (pre-forwarder deployment) have the Universal Forwarder installed and the Windows Add-on (apps/Splunk_TA_windows). I also have systems with just the Universal Forwarder. I did some playing with the Add-on config, trying out the perfmon, etc. My assumption was that the Add-on has more functionality that the Universal Forwarder alone. However, I cannot find documentation to show that. Also, I copied the inputs.conf from the Add-on from one system to the inputs.conf file on a system with only the Universal Forwarder. There has been no change in the data. So what does the Add-on do? Event Log, performance data, etc all look identical whether the Add-on is installed or not. I am not referring to the Splunk indexer, which is on Linux. I'm talking about the clients. Do I need to deploy the Splunk_TA_windows app or just a custom app with the necessary conf files? I'm only looking for Windows event logs and a couple of performance stats. Can some one help straighten me out?

0 Karma

lguinn2
Legend

The Splunk for Windows TA does not have "more functionality" than the UF alone. The TA simply sets up certain inputs for you, and does it in a way that is compatible with the reporting provided by the Splunk for Windows app - which you could install on your indexers/search head. If you aren't going to use the Splunk for Windows app, you don't need the Splunk for Windows TA on the forwarders. You could use it to set the data collection if you want.

But for what you want to do, you could certainly use a custom app with just the necessary conf files. The custom app would probably be easier than installing the TA and then having to disable the parts that you don't care about.

bbeavise2g
Explorer

That helps a lot. Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...