Getting Data In

Indexing evt files in a distributed environment

MHibbin
Influencer

All,

Just a quick query on monitoring exported evt files...

We are looking to use linux for our Indexers, however as some of our data will come from Windows based machines, we initially were looking at importing the data from WMI (installationg of a Universal Forwarder is not an option). However, as the remote Windows machines are not connected to the AD (only use local authentication), we are looking at using a Windows based forwarder, as it has access to the Windows processors for evt files. Is there any restriction on the type of forwarder used (e.g. Universal, of Light-weight)? - I wasn't sure of the level of event processing from the forwarder, before passing it to the Linux based Indexer?.

I know I will have to use automatic sourcetyping, which will allow Splunk to detect the evt/evtx file extension and process it correctly.

Any thoughts welcome.

Thanks in advance,

MHibbin

Runals
Motivator

I'm confused - you can or can't install a local Splunk agent? If you are able to use one then it doesn't matter that your indexers are Linux or even if they aren't in the same domain. If you can't use a Splunk UF you probably can't use a Snare agent either but is another option. The data format sort of sucks once it is in Splunk (tab delimited and multiple spaces make field definition a pain) but at least it would be in Splunk. If your Windows machines are Win7/Win2k8 you could look into native event forwarding to another Win2k8 server and put a Splunk agent on it. I haven't ever tried that and don't know if there are limitations given your AD situation.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...