Deployment Architecture

Why am I seeing windows messages in a Linux UWF?

a212830
Champion

Hi,

I noticed this in my Linux UFW splunkd.log:

12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "WinNetMon://" with 15 parameters: remoteAddress, process, user, addressFamily, packetType, direction, protocol, readInterval, driverBufferSize, userBufferSize, mode, multikvMaxEventCount, multikvMaxTimeMs, disabled, index
12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "WinPrintMon://" with 4 parameters: type, baseline, disabled, index
12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "WinRegMon://" with 7 parameters: proc, hive, type, baseline, baseline_interval, disabled, index
12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "admon://" with 7 parameters: targetDc, startingNode, monitorSubtree, disabled, index, printSchema, baseline
12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "perfmon://" with 10 parameters: object, counters, instances, interval, mode, samplingInterval, stats, disabled, index, showZeroValue

Why is a Linux UFW reporting on Windows monitors?

Tags (2)
0 Karma

Richfez
SplunkTrust
SplunkTrust

I don't know if you have resolved this or not, but my first guess would be that the Splunk_TA_windows got deployed to the *nix UF, possibly via a deployment server if you use one.

You could check this with the btool command, which on *nix if you installed in the default location would be /opt/splunk/bin/splunk cmd btool --debug inputs list or to specifically just see one of the above, perhaps /opt/splunk/bin/splunk cmd btool --debug inputs list WinRegMon.

That should output from which app the input stanzas are being read. Once you have the app name/directory, you could do a little manual sleuthing to see if you can figure out how it got there.

0 Karma
Get Updates on the Splunk Community!

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Community Content Calendar, October Edition

Welcome to the October edition of our Community Spotlight! The Splunk Community is a treasure trove of ...