Getting Data In

Windows Event collection - A really basic question, Doh

kevbod
New Member

Guys, I want to use Splunk for some eval work on Windows 7 prof and server 2008 and 2012. I want to stick strictly to Universal Forwarders and not WMI. Am i reading this document link correctly below?

http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorwindowsdata

The words "Splunk Enterprise must run on Windows" says to me I have no option other than a Windows install of Splunk Enterprise and therefore my currently built Splunk Enterprise Red Hat server install is not fit for this purpose?

The documentation is good but pulling these simple strings together is not easy. Can anyone point me to a document that will answer these questions please?

0 Karma

Runals
Motivator

Nah - you are fine. Put the appropriate UFs on your Windows devices and have the data sent back to your Red Hat indexer(s). I get why the document looks confusing but haven't had any caffeine yet so can't concisely reword it.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...