Getting Data In

How to deploy Splunk and collect 10,000+ Windows logs? Does anyone have any good documentation or advice to provide me?

bobbieluturner
New Member

I am a newbie - I've been tasked with deploying Splunk and collecting 10,000+ Windows logs... Anyone got any good whitepaper or advice to provide me?

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Hi bobbieluturner,
to add to woodcock's comments...
What exactly does that mean: 10,000+ Windows logs? Are you referring to logs from 10k+ Windows hosts?
What kinds of logs, what log volume are you expecting per day?

But simply the fact that you mentioned 10,000+ anything, I would answer by saying that you need more than just a white paper. Are you already a customer? If so, you should have access to a pre-sales technical resource to help you with this.

If not, starting at our documentation here is not a bad idea. You'll probably need to read up on
- proper sizing given your expected daily log data volume, data retention, search volume and concurrent users
- recommended hardware specs
- general Splunk architecture (forwarding, indexing, search)
- managing your deployment (configuration management with Deployment Server)
- how to get data in properly (timestamping, source typing, line breaking, etc.)

If you update your question with a bit more detail of what your target deployment is supposed to provide, the community may be able to give you a more targeted answer.

Good luck, and welcome to the world of Splunk! 🙂
Stefan

0 Karma

tom_frotscher
Builder

Hi,

as a first look, use the offical splunk docs.

For example how to install: here
or about getting windows data into splunk: here

Greetings

Tom

woodcock
Esteemed Legend

How many servers? What is the post-backlog daily bandwidth (GB/day of raw data) overall? Are these actually "logs" or is it WMI? Do you have any aggregation agents currently deployed (e.g. Snare)? If you would like to get any kind of useful responses you will need to give much more detail.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...