Getting Data In

Indexing evt files in a distributed environment

MHibbin
Influencer

All,

Just a quick query on monitoring exported evt files...

We are looking to use linux for our Indexers, however as some of our data will come from Windows based machines, we initially were looking at importing the data from WMI (installationg of a Universal Forwarder is not an option). However, as the remote Windows machines are not connected to the AD (only use local authentication), we are looking at using a Windows based forwarder, as it has access to the Windows processors for evt files. Is there any restriction on the type of forwarder used (e.g. Universal, of Light-weight)? - I wasn't sure of the level of event processing from the forwarder, before passing it to the Linux based Indexer?.

I know I will have to use automatic sourcetyping, which will allow Splunk to detect the evt/evtx file extension and process it correctly.

Any thoughts welcome.

Thanks in advance,

MHibbin

Runals
Motivator

I'm confused - you can or can't install a local Splunk agent? If you are able to use one then it doesn't matter that your indexers are Linux or even if they aren't in the same domain. If you can't use a Splunk UF you probably can't use a Snare agent either but is another option. The data format sort of sucks once it is in Splunk (tab delimited and multiple spaces make field definition a pain) but at least it would be in Splunk. If your Windows machines are Win7/Win2k8 you could look into native event forwarding to another Win2k8 server and put a Splunk agent on it. I haven't ever tried that and don't know if there are limitations given your AD situation.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...