I have an environment where it's going to be a hassle to add a new Windows server. However, we have a file on a Windows server we would like to monitor and log. Is it possible to do that from a Linux Heavy Forwarder? Using samba/cifs so we can map the drive?
Or, as this answer implies
will that cause more problems then it's worth?
Thanks.
Hello,
you can install a windows forwarder on that server and monitor the file and send it straight to your linux splunk heavy forwarder, or directly to the indexer tier
hope it helps
Thanks, but (and I should have mentioned this in the original post) I am not permitted to install a windows forwarder on the windows server. Hence the question about the work around.