All Apps and Add-ons

add additional server to windows app

benwaynet
Engager

Just installed splunk for first time. When I first ran the windows app it scanned the localhost and started collecting numerous WMI and logs by default. Is there an easy way to add additional windows servers to be monitored and have them collect these same WMI and logs?

Right now I can only find a way to add addition remote eventlog monitoring.

I'm think one location where I put a server name and it scans for all the different types of inputs and reports which it can find and lets you pick what you want to monitor.

thanks,jb

Voltaire
Communicator

It depends upon what type of information you are trying to obtain from the other servers. The most comprehensive method would be to configure the other servers as either a Splunk light forwarder or as a Forwarder. ( refer to the admin manual page 90 for a detailed explanation )

Hope that helps!

bbrendon
New Member

so basically you need to install splunk on all windows servers and configure the installation to forward the information to the master. correct?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...