Getting Data In

Collecting data from Windows host without forwarder or domain group

MHibbin
Influencer

Hi all,

I was wondering if anyone has had experience of collecting remote data for Splunk from a Windows device, where a forwarder can not be installed on the machine (due to support issues), and the device uses local authentication (i.e. is not in an AD domain group). Preferably not installing a third party file either.

Any thoughts on how this could be achieved? - obviously linux has native tools available to make this easy, apparently not with Windows.

Thanks in advance,

MHibbin

0 Karma
1 Solution

Kate_Lawrence-G
Contributor

Hi,

I can only think of 2 possible options:

  1. Remotely monitor the box over WMI - http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/MonitorWindowsdata#Configure_remote_event_log...
  2. Or write a VB/Powershell script to get everything into a remote share that splunk can read it from there - http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Thanks!

Kate

View solution in original post

Kate_Lawrence-G
Contributor

Hi,

I can only think of 2 possible options:

  1. Remotely monitor the box over WMI - http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/MonitorWindowsdata#Configure_remote_event_log...
  2. Or write a VB/Powershell script to get everything into a remote share that splunk can read it from there - http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Thanks!

Kate

MHibbin
Influencer

Thanks for the answer @Kate_Lawrence. However, as mentioned the windows machine does not use AD for authentication, WMI is out of the question (option #1).

We are going to look into sending the data using something like psftp/pscp to a windows forwarder and then have the EVTs/logs read/forwarded from there.

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...