Getting Data In

Collecting data from Windows host without forwarder or domain group

MHibbin
Influencer

Hi all,

I was wondering if anyone has had experience of collecting remote data for Splunk from a Windows device, where a forwarder can not be installed on the machine (due to support issues), and the device uses local authentication (i.e. is not in an AD domain group). Preferably not installing a third party file either.

Any thoughts on how this could be achieved? - obviously linux has native tools available to make this easy, apparently not with Windows.

Thanks in advance,

MHibbin

0 Karma
1 Solution

Kate_Lawrence-G
Contributor

Hi,

I can only think of 2 possible options:

  1. Remotely monitor the box over WMI - http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/MonitorWindowsdata#Configure_remote_event_log...
  2. Or write a VB/Powershell script to get everything into a remote share that splunk can read it from there - http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Thanks!

Kate

View solution in original post

Kate_Lawrence-G
Contributor

Hi,

I can only think of 2 possible options:

  1. Remotely monitor the box over WMI - http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/MonitorWindowsdata#Configure_remote_event_log...
  2. Or write a VB/Powershell script to get everything into a remote share that splunk can read it from there - http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Thanks!

Kate

MHibbin
Influencer

Thanks for the answer @Kate_Lawrence. However, as mentioned the windows machine does not use AD for authentication, WMI is out of the question (option #1).

We are going to look into sending the data using something like psftp/pscp to a windows forwarder and then have the EVTs/logs read/forwarded from there.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...