Getting Data In

Windows Event collection - A really basic question, Doh

kevbod
New Member

Guys, I want to use Splunk for some eval work on Windows 7 prof and server 2008 and 2012. I want to stick strictly to Universal Forwarders and not WMI. Am i reading this document link correctly below?

http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorwindowsdata

The words "Splunk Enterprise must run on Windows" says to me I have no option other than a Windows install of Splunk Enterprise and therefore my currently built Splunk Enterprise Red Hat server install is not fit for this purpose?

The documentation is good but pulling these simple strings together is not easy. Can anyone point me to a document that will answer these questions please?

0 Karma

Runals
Motivator

Nah - you are fine. Put the appropriate UFs on your Windows devices and have the data sent back to your Red Hat indexer(s). I get why the document looks confusing but haven't had any caffeine yet so can't concisely reword it.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...