Getting Data In

How to push Windows event and security logs to a *NIX Splunk server without deploying forwarders on the Windows servers?

judenaidoo
New Member

According to my understanding, WMI as a pull agent is available on Windows' deployment of Splunk only.

What are the options for either pushing logs from any native Windows server app, or pulling via any native *UNIX app where Splunk is deployed to get Windows event and security logs ?

The customer does NOT want to deploy forwarders on all his Windows servers.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

I'll comment that perhaps your customer is being a little short-sighted, but okay.

WMI as a pull-agent is available only on Windows, and is really undesirable. It requires lots more bandwidth and processing on each server. What you might be able to do is something like this:

You could use Windows Native Log forwarding via GPO to forward logs from all of your Windows servers to a single Windows-based collection node, and then run a forwarder on it. Similarly, have all of your *nix boxes use syslog forwarding to forward to a syslog-ng server and run a forwarder there to pick up.

You wind up with two extra servers - one Windows, one Unix - but no forwarders anywhere else.

0 Karma

judenaidoo
New Member

@dwaddle - Thanks for the prompt response. Yes, my customer is being a little short-sighted, but understandably so, as they have circa 300 MS servers and are very risk averse. The problem is limited just to the Windows environment, and I've proposed the idea of event-log forwarding to another windows server vm with a forwarder on there. I just wanted to see if there was any other option.
Thanks again for your input.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...