Getting Data In

Indexing evt files in a distributed environment

MHibbin
Influencer

All,

Just a quick query on monitoring exported evt files...

We are looking to use linux for our Indexers, however as some of our data will come from Windows based machines, we initially were looking at importing the data from WMI (installationg of a Universal Forwarder is not an option). However, as the remote Windows machines are not connected to the AD (only use local authentication), we are looking at using a Windows based forwarder, as it has access to the Windows processors for evt files. Is there any restriction on the type of forwarder used (e.g. Universal, of Light-weight)? - I wasn't sure of the level of event processing from the forwarder, before passing it to the Linux based Indexer?.

I know I will have to use automatic sourcetyping, which will allow Splunk to detect the evt/evtx file extension and process it correctly.

Any thoughts welcome.

Thanks in advance,

MHibbin

Runals
Motivator

I'm confused - you can or can't install a local Splunk agent? If you are able to use one then it doesn't matter that your indexers are Linux or even if they aren't in the same domain. If you can't use a Splunk UF you probably can't use a Snare agent either but is another option. The data format sort of sucks once it is in Splunk (tab delimited and multiple spaces make field definition a pain) but at least it would be in Splunk. If your Windows machines are Win7/Win2k8 you could look into native event forwarding to another Win2k8 server and put a Splunk agent on it. I haven't ever tried that and don't know if there are limitations given your AD situation.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...