Getting Data In

Possible to run Splunk on Windows and Linux in the same environment?

horsefez
Motivator

Hi there,

I would like to know if it's possible to have Splunk instances running on linux and windows in the same environment.

We currently have an environment which runs splunk on x86 linux centOS virtual machines.
My company decided to monitor Active Directory security events with splunk.

According to this documentation: http://docs.splunk.com/Documentation/Splunk/6.2.9/Data/AuditActiveDirectory
I need to run splunk on windows to monitor active directory systems.


1. Am I able to just install another indexer on windows and add this one to the existing linux environment?
2. Will this work together?
3. Can this indexer share the licence pool of the existing splunk linux environment?
4. Can I forward data from the windows indexer to the linux indexers?

Kind regards,
pyro_wood

0 Karma
1 Solution

somesoni2
Revered Legend

Ans1. You just need a Heavy forwarder installed on Windows to monitor AD and that HF can send data to your existing Linux Indexer(s).
Ans2. Yes, it'll
Ans3. it's a HF so it has to share the same license pool, and yes it can
Ans4. As mentioned earlier, you need a Heavy forwarder and it'll forwarder the data to your linux indexers.

View solution in original post

somesoni2
Revered Legend

Ans1. You just need a Heavy forwarder installed on Windows to monitor AD and that HF can send data to your existing Linux Indexer(s).
Ans2. Yes, it'll
Ans3. it's a HF so it has to share the same license pool, and yes it can
Ans4. As mentioned earlier, you need a Heavy forwarder and it'll forwarder the data to your linux indexers.

horsefez
Motivator

Perfect, thank you very much 🙂

0 Karma

tred23
Path Finder

Rock On! This is the exact question I was searching for today and the answer is spot on.

Thank you @pyro_wood and @somesoni2. Ya'll made my day.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...