Getting Data In

How to push Windows event and security logs to a *NIX Splunk server without deploying forwarders on the Windows servers?

judenaidoo
New Member

According to my understanding, WMI as a pull agent is available on Windows' deployment of Splunk only.

What are the options for either pushing logs from any native Windows server app, or pulling via any native *UNIX app where Splunk is deployed to get Windows event and security logs ?

The customer does NOT want to deploy forwarders on all his Windows servers.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

I'll comment that perhaps your customer is being a little short-sighted, but okay.

WMI as a pull-agent is available only on Windows, and is really undesirable. It requires lots more bandwidth and processing on each server. What you might be able to do is something like this:

You could use Windows Native Log forwarding via GPO to forward logs from all of your Windows servers to a single Windows-based collection node, and then run a forwarder on it. Similarly, have all of your *nix boxes use syslog forwarding to forward to a syslog-ng server and run a forwarder there to pick up.

You wind up with two extra servers - one Windows, one Unix - but no forwarders anywhere else.

0 Karma

judenaidoo
New Member

@dwaddle - Thanks for the prompt response. Yes, my customer is being a little short-sighted, but understandably so, as they have circa 300 MS servers and are very risk averse. The problem is limited just to the Windows environment, and I've proposed the idea of event-log forwarding to another windows server vm with a forwarder on there. I just wanted to see if there was any other option.
Thanks again for your input.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...