Getting Data In

WMI and *NIX

xradim
Explorer

Hi,

I have walked through settings related to WMI and *NIX. I could see there is setting field related to credentials I would like to know what is the original design.

Is it possible to setup *NIX Splunk to collect data through WMI? I would be expecting it is possible but don't know the design.
I know I can do it with Windows Splunk installation, but would like to stay with one platform.

Thanks

Tags (1)
0 Karma

David
Splunk Employee
Splunk Employee

You can't monitor wmi from a *NIX server, unfortunately. What you can do, though, is set up a Windows box as a forwarder, have it grab the data via wmi and shoot it over to your *NIX Indexer. Or just install forwarders on the Windows boxes themselves, depending on your needs.

http://www.splunk.com/support/forum:SplunkAdministration/2432

getbman
New Member

Thank you for your answer on setting up a Windows box as a forwarder as a WMI proxy. By going down this path you are able to collect data - however the Windows App still expects WMI - is there a way to get the Windows App to work on a *nix installation of Splunk?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...