Getting Data In

Splunk Universal Forwarder on Win 2000?

tpaulsen
Contributor

Hallo,

we know it´s not supported officially, but we have some very old Windows 2000 server, that won´t be upgraded before next year, but we need to install Splunk on them. Will the Universal Forwarder work on Windows 2000?

Thank you!

0 Karma
1 Solution

fcorbin
Engager

I think there may be a difference between the forwarder and the configuration I have, but I have yet to figure out what it is, so here's what I know...

I installed Splunk 4.2.1 (Enterprise trial, but since then the trial ran out, so I am running the free license now). Go to Manager > Forwarding and receiving > Forwarding defaults, chose not to store local copy of the events (otherwise I guess this would be an indexer as well). Then go to Configure forwarding and add the host you want to send data to.

good luck...

View solution in original post

0 Karma

mendesjo
Path Finder

I've tested upto 5.0 works..

0 Karma

tpaulsen
Contributor

Yep 4.2.1 works on Win 2000.

0 Karma

tpaulsen
Contributor

fcorbin, thank you, i guess than Splunk> does not try to force you to install on only supported plattforms like other products (BMC....) do...

0 Karma

fcorbin
Engager

I think there may be a difference between the forwarder and the configuration I have, but I have yet to figure out what it is, so here's what I know...

I installed Splunk 4.2.1 (Enterprise trial, but since then the trial ran out, so I am running the free license now). Go to Manager > Forwarding and receiving > Forwarding defaults, chose not to store local copy of the events (otherwise I guess this would be an indexer as well). Then go to Configure forwarding and add the host you want to send data to.

good luck...

0 Karma

tpaulsen
Contributor

Hello, thank you. Did you install the Splunk Forwarder 4.2.1?

0 Karma

fcorbin
Engager

I am new to Splunk so there may be things I haven't seen. FWIW, I installed Splunk as an indexer on a Win 2000 server and it worked fine. I later converted that machine to be a forwarder and it still works fine.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...