Getting Data In

How to push Windows event and security logs to a *NIX Splunk server without deploying forwarders on the Windows servers?

judenaidoo
New Member

According to my understanding, WMI as a pull agent is available on Windows' deployment of Splunk only.

What are the options for either pushing logs from any native Windows server app, or pulling via any native *UNIX app where Splunk is deployed to get Windows event and security logs ?

The customer does NOT want to deploy forwarders on all his Windows servers.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

I'll comment that perhaps your customer is being a little short-sighted, but okay.

WMI as a pull-agent is available only on Windows, and is really undesirable. It requires lots more bandwidth and processing on each server. What you might be able to do is something like this:

You could use Windows Native Log forwarding via GPO to forward logs from all of your Windows servers to a single Windows-based collection node, and then run a forwarder on it. Similarly, have all of your *nix boxes use syslog forwarding to forward to a syslog-ng server and run a forwarder there to pick up.

You wind up with two extra servers - one Windows, one Unix - but no forwarders anywhere else.

0 Karma

judenaidoo
New Member

@dwaddle - Thanks for the prompt response. Yes, my customer is being a little short-sighted, but understandably so, as they have circa 300 MS servers and are very risk averse. The problem is limited just to the Windows environment, and I've proposed the idea of event-log forwarding to another windows server vm with a forwarder on there. I just wanted to see if there was any other option.
Thanks again for your input.

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...