Getting Data In

Splunk Universal Forwarder on Win 2000?

tpaulsen
Contributor

Hallo,

we know it´s not supported officially, but we have some very old Windows 2000 server, that won´t be upgraded before next year, but we need to install Splunk on them. Will the Universal Forwarder work on Windows 2000?

Thank you!

0 Karma
1 Solution

fcorbin
Engager

I think there may be a difference between the forwarder and the configuration I have, but I have yet to figure out what it is, so here's what I know...

I installed Splunk 4.2.1 (Enterprise trial, but since then the trial ran out, so I am running the free license now). Go to Manager > Forwarding and receiving > Forwarding defaults, chose not to store local copy of the events (otherwise I guess this would be an indexer as well). Then go to Configure forwarding and add the host you want to send data to.

good luck...

View solution in original post

0 Karma

mendesjo
Path Finder

I've tested upto 5.0 works..

0 Karma

tpaulsen
Contributor

Yep 4.2.1 works on Win 2000.

0 Karma

tpaulsen
Contributor

fcorbin, thank you, i guess than Splunk> does not try to force you to install on only supported plattforms like other products (BMC....) do...

0 Karma

fcorbin
Engager

I think there may be a difference between the forwarder and the configuration I have, but I have yet to figure out what it is, so here's what I know...

I installed Splunk 4.2.1 (Enterprise trial, but since then the trial ran out, so I am running the free license now). Go to Manager > Forwarding and receiving > Forwarding defaults, chose not to store local copy of the events (otherwise I guess this would be an indexer as well). Then go to Configure forwarding and add the host you want to send data to.

good luck...

0 Karma

tpaulsen
Contributor

Hello, thank you. Did you install the Splunk Forwarder 4.2.1?

0 Karma

fcorbin
Engager

I am new to Splunk so there may be things I haven't seen. FWIW, I installed Splunk as an indexer on a Win 2000 server and it worked fine. I later converted that machine to be a forwarder and it still works fine.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...