Deployment Architecture

Why am I seeing windows messages in a Linux UWF?

a212830
Champion

Hi,

I noticed this in my Linux UFW splunkd.log:

12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "WinNetMon://" with 15 parameters: remoteAddress, process, user, addressFamily, packetType, direction, protocol, readInterval, driverBufferSize, userBufferSize, mode, multikvMaxEventCount, multikvMaxTimeMs, disabled, index
12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "WinPrintMon://" with 4 parameters: type, baseline, disabled, index
12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "WinRegMon://" with 7 parameters: proc, hive, type, baseline, baseline_interval, disabled, index
12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "admon://" with 7 parameters: targetDc, startingNode, monitorSubtree, disabled, index, printSchema, baseline
12-08-2014 20:39:00.162 -0500 INFO SpecFiles - Found external scheme definition for stanza "perfmon://" with 10 parameters: object, counters, instances, interval, mode, samplingInterval, stats, disabled, index, showZeroValue

Why is a Linux UFW reporting on Windows monitors?

Tags (2)
0 Karma

Richfez
SplunkTrust
SplunkTrust

I don't know if you have resolved this or not, but my first guess would be that the Splunk_TA_windows got deployed to the *nix UF, possibly via a deployment server if you use one.

You could check this with the btool command, which on *nix if you installed in the default location would be /opt/splunk/bin/splunk cmd btool --debug inputs list or to specifically just see one of the above, perhaps /opt/splunk/bin/splunk cmd btool --debug inputs list WinRegMon.

That should output from which app the input stanzas are being read. Once you have the app name/directory, you could do a little manual sleuthing to see if you can figure out how it got there.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...