Getting Data In

Automatically detect new windows hosts for WMI data collection?

wilhelmF
Path Finder

Our company has a cloud. For the cloud VMs we don't want to install Splunk Agents on every new VM and therefore we would like to receive the Windows Events via WMI. We know about the disatvantages but we need to go down this road. My question is there a way that we can automatically collect eventlogs from every new VM without specifing the new VM in the conf file?

0 Karma

FrankVl
Ultra Champion

Only thing I can think of is somehow automating the maintenance of the conf file. Set up some script that gets an updated list of hosts from some source (AD?) and generates the required WMI configuration for each of them.

An alternative could be to look at using Windows Event Forwarding, to sent events from all your VMs to a smaller set of collectors, on which you then install a Universal Forwarder to collect and forward the logs. Windows Event Fowarding (using source initiated subscriptions) can be managed through GPOs and in such a way that I think it should work in such a dynamic environment (although you might have some challenges properly distributing the load across the collectors, but that also depends on how large the environment is).

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...