Getting Data In

Collecting data from Windows host without forwarder or domain group

MHibbin
Influencer

Hi all,

I was wondering if anyone has had experience of collecting remote data for Splunk from a Windows device, where a forwarder can not be installed on the machine (due to support issues), and the device uses local authentication (i.e. is not in an AD domain group). Preferably not installing a third party file either.

Any thoughts on how this could be achieved? - obviously linux has native tools available to make this easy, apparently not with Windows.

Thanks in advance,

MHibbin

0 Karma
1 Solution

Kate_Lawrence-G
Contributor

Hi,

I can only think of 2 possible options:

  1. Remotely monitor the box over WMI - http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/MonitorWindowsdata#Configure_remote_event_log...
  2. Or write a VB/Powershell script to get everything into a remote share that splunk can read it from there - http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Thanks!

Kate

View solution in original post

Kate_Lawrence-G
Contributor

Hi,

I can only think of 2 possible options:

  1. Remotely monitor the box over WMI - http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/MonitorWindowsdata#Configure_remote_event_log...
  2. Or write a VB/Powershell script to get everything into a remote share that splunk can read it from there - http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Thanks!

Kate

MHibbin
Influencer

Thanks for the answer @Kate_Lawrence. However, as mentioned the windows machine does not use AD for authentication, WMI is out of the question (option #1).

We are going to look into sending the data using something like psftp/pscp to a windows forwarder and then have the EVTs/logs read/forwarded from there.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...