Getting Data In

Is there a version of Splunk Universal Forwarder that is compatible with NT4?

sentiaglobal
New Member

Hi folks,

You'll have to excuse my memory lapse here - Splunk forwarder on NT4, installation of - I recall getting an old version of the forwarder to install on NT4 some time back, but the version is no longer available & I don't have the installer - needless to say this is going to be needed in a critical environment where they still run NT4!

Guessing support for NT4 has never been official, so I'm wondering if any of you are using other methods which ARE supported like WMI to retrieve the data?

0 Karma
1 Solution

jcrabb_splunk
Splunk Employee
Splunk Employee

NT4 EOL was on Dec 31st 2004 which is before "Splunk" was founded. Going back through our available documentation, I am unable to find a UF version which supported that platform, but its possible that a very early version could have. Most definitely, none of our currently available products support it.

Jacob
Sr. Technical Support Engineer

View solution in original post

jcrabb_splunk
Splunk Employee
Splunk Employee

NT4 EOL was on Dec 31st 2004 which is before "Splunk" was founded. Going back through our available documentation, I am unable to find a UF version which supported that platform, but its possible that a very early version could have. Most definitely, none of our currently available products support it.

Jacob
Sr. Technical Support Engineer

lakromani
Builder

They should use resource on upgrade the NT4 to some later, not time to find forwarder working with it.
It's out of support on every way and a security risk to use.

0 Karma

kungfu71186
New Member

You should be able to use WMI. Haven't tried it yet, but as long as you can query from WMI, I don't see why it shouldn't work.

0 Karma

JDukeSplunk
Builder

So I'm guessing the 4.3 universal forwader on the site is not old enough?

https://www.splunk.com/page/download_track?file=4.3/windows/splunkforwarder-4.3-115073-x86-release.m...

0 Karma

sentiaglobal
New Member

Correct 🙂

0 Karma

JDukeSplunk
Builder

Bummer. I dug through as many search engines as i could find looking for maybe a hidden FTP mirror for Splunk downloads. Nothing.

Maybe you could use SNMP to offload the NT4 traffic elsewhere and then Splunk that? I don't know what you would be able to capture for it. Personally, I'd keep searching or maybe post a new question here "Looking for universal forwarder install older than 4.3".

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...