Deployment Architecture

クライアント管理の方法について,クライアントのログオン、ログオフの情報収集について About client management method, about client logon and logoff information collection

New Member

クライアント端末をSplunk 上で管理する方法を教えてください。
バージョンはSplunk Enterprise 7.1.2となります。

どのようにインストールを行えばよいのでしょうか?,Splunk Enterprise 7.1.2を使用しています。


English translation:

How do I manage client terminals on Splunk?
The version is Splunk Enterprise 7.1.2.

I think that it is necessary to install agent etc.
How do I install it? , I am using Splunk Enterprise 7.1.2.

I would like to collect information on 74 client terminals logging in and logging off.
Therefore, I think that it is necessary to register the management client to the server first, please tell me how to set it

0 Karma

Splunk Employee
Splunk Employee

AD でドメイン認証している場合は、ADサーバにWindows版のSplunkを入れれば、簡単にイベントログが取得できます。
AD でドメイン認証していない場合は、各端末からログを集める必要がありますが、方法は、

1.各端末にWindows 版 Universal Forwarderを入れて、別途Splunkサーバを1台たて、このSplunkサーバにイベントログを転送して集める
2.別の仕組み(いろんなエンドポイントのソフトがありますので)でイベントログを集めて、集めたサーバ上にWindows 版 Universal Forwarderを入れて、別途Splunkサーバを1台たて、このSplunkサーバにイベントログを転送して集める


0 Karma






0 Karma


Hi there,

You should first install Splunk Universal forwarders (splunk agents which are used to collect data) on your client terminals

After that, you need to specify the deployment server (DS) that you want the client to connect to; as described here.

Configure outputs on forwarders.

Verify all your clients are connected and making calls to DS. Go to "Forwarder Management" under settings and check "Phone Home" column in "Clients" tab.

Figure out where your data is located on host(s) (AKA deployment client).

Create a deployment app. This app must have inputs.conf and any other necessary .conf (usually props.conf and transforms.conf) files.

Deploy this app to deployment client.

Verify data in splunk.

Please refer to splunk docs/answers if you're struck.

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...