Getting Data In

How to deploy Splunk and collect 10,000+ Windows logs? Does anyone have any good documentation or advice to provide me?

bobbieluturner
New Member

I am a newbie - I've been tasked with deploying Splunk and collecting 10,000+ Windows logs... Anyone got any good whitepaper or advice to provide me?

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Hi bobbieluturner,
to add to woodcock's comments...
What exactly does that mean: 10,000+ Windows logs? Are you referring to logs from 10k+ Windows hosts?
What kinds of logs, what log volume are you expecting per day?

But simply the fact that you mentioned 10,000+ anything, I would answer by saying that you need more than just a white paper. Are you already a customer? If so, you should have access to a pre-sales technical resource to help you with this.

If not, starting at our documentation here is not a bad idea. You'll probably need to read up on
- proper sizing given your expected daily log data volume, data retention, search volume and concurrent users
- recommended hardware specs
- general Splunk architecture (forwarding, indexing, search)
- managing your deployment (configuration management with Deployment Server)
- how to get data in properly (timestamping, source typing, line breaking, etc.)

If you update your question with a bit more detail of what your target deployment is supposed to provide, the community may be able to give you a more targeted answer.

Good luck, and welcome to the world of Splunk! 🙂
Stefan

0 Karma

tom_frotscher
Builder

Hi,

as a first look, use the offical splunk docs.

For example how to install: here
or about getting windows data into splunk: here

Greetings

Tom

woodcock
Esteemed Legend

How many servers? What is the post-backlog daily bandwidth (GB/day of raw data) overall? Are these actually "logs" or is it WMI? Do you have any aggregation agents currently deployed (e.g. Snare)? If you would like to get any kind of useful responses you will need to give much more detail.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...