Getting Data In

How to push Windows event and security logs to a *NIX Splunk server without deploying forwarders on the Windows servers?

judenaidoo
New Member

According to my understanding, WMI as a pull agent is available on Windows' deployment of Splunk only.

What are the options for either pushing logs from any native Windows server app, or pulling via any native *UNIX app where Splunk is deployed to get Windows event and security logs ?

The customer does NOT want to deploy forwarders on all his Windows servers.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

I'll comment that perhaps your customer is being a little short-sighted, but okay.

WMI as a pull-agent is available only on Windows, and is really undesirable. It requires lots more bandwidth and processing on each server. What you might be able to do is something like this:

You could use Windows Native Log forwarding via GPO to forward logs from all of your Windows servers to a single Windows-based collection node, and then run a forwarder on it. Similarly, have all of your *nix boxes use syslog forwarding to forward to a syslog-ng server and run a forwarder there to pick up.

You wind up with two extra servers - one Windows, one Unix - but no forwarders anywhere else.

0 Karma

judenaidoo
New Member

@dwaddle - Thanks for the prompt response. Yes, my customer is being a little short-sighted, but understandably so, as they have circa 300 MS servers and are very risk averse. The problem is limited just to the Windows environment, and I've proposed the idea of event-log forwarding to another windows server vm with a forwarder on there. I just wanted to see if there was any other option.
Thanks again for your input.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...