Getting Data In

Will Splunk WMI inputs work on servers not in same domain?

maverick
Splunk Employee
Splunk Employee

I need to set up WMI polling on my Windows boxes that cannot run agents or belong to a domain.

With Splunk, is it possible to use local accounts for WMI polling provided that the permissions are set correctly?

0 Karma

maverick
Splunk Employee
Splunk Employee

If the machines are not in a domain, then you can query them from another stand-alone Windows server if the user name (i.e. the name Splunk is installed as on the collector) also exists as a local administrator on the target machine(s).

e.g. install splunk as myhost\foo, where $everyremotehost also has an account ‘foo’ with sufficient (probably local administrator) permissions.

Note: you will probably want to wrap that in a VPN or native IPSec, as without a domain, Windows reverts to NTLMv2, which I believe is crackable.

0 Karma

maverick
Splunk Employee
Splunk Employee

thanks and corrected!

0 Karma

mw
Splunk Employee
Splunk Employee

Your backslash was lost in myhost\foo

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...