Getting Data In

Splunk for Windows on a Splunk Cluster

agodoy
Communicator

Has anyone does this yet? I am looking to see what pieces should be installed in the search pears and what pieces on the search head. Do I need to install the App twice (once on search head and once to search peers)?

So far I have a Windows Forwarder with the Windows TA sending data to Splunk Cluster. I can search the Windows data from the search head. However, when I use the Windows App, some of the widgets are not populating as expected. Also, the drop down are not populating.

Any ideas?

0 Karma
1 Solution

agodoy
Communicator

Never mind. I just had to be patient and wait for the lookup tables to build. Works as expected.

View solution in original post

agodoy
Communicator

Never mind. I just had to be patient and wait for the lookup tables to build. Works as expected.

jbernt_splunk
Splunk Employee
Splunk Employee

Hello!

Where is the Windows app installed if not on the search head?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...