Getting Data In

Forwarding remote WMI information

fnsbsd
New Member

I need to configure a universal forwarder to remotely collect WMI information (eventlogs) from various Windows hosts, and then forward that information to my indexer. I have the universal forwarder up and running, and it is successfully forwarding local information to my indexer.

I believe I need to write a WMI.conf file, but I don't know what to put in it. Can someone post an example of what it should look like, or tell me if I should be using a light forwarder instead?

Thank you.

0 Karma

MarioM
Motivator

if you download to your UF the Splunk for Windows technology add-on it has, in default folder, a wmi.conf with examples ie:

[WMI:LocalSecurity]
interval = 10
event_log_file = Security
index = default
disabled = 0

[WMI:LocalProcesses]
interval = 30
wql = SELECT Name, IDProcess, PrivateBytes, PercentProcessorTime FROM Win32_PerfFormattedData_PerfProc_Process
index = default
disabled = 0
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...