Getting Data In

Will Splunk WMI inputs work on servers not in same domain?

maverick
Splunk Employee
Splunk Employee

I need to set up WMI polling on my Windows boxes that cannot run agents or belong to a domain.

With Splunk, is it possible to use local accounts for WMI polling provided that the permissions are set correctly?

0 Karma

maverick
Splunk Employee
Splunk Employee

If the machines are not in a domain, then you can query them from another stand-alone Windows server if the user name (i.e. the name Splunk is installed as on the collector) also exists as a local administrator on the target machine(s).

e.g. install splunk as myhost\foo, where $everyremotehost also has an account ‘foo’ with sufficient (probably local administrator) permissions.

Note: you will probably want to wrap that in a VPN or native IPSec, as without a domain, Windows reverts to NTLMv2, which I believe is crackable.

0 Karma

maverick
Splunk Employee
Splunk Employee

thanks and corrected!

0 Karma

mw
Splunk Employee
Splunk Employee

Your backslash was lost in myhost\foo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...