Getting Data In

Windows Subsystem for Linux logging

mdmosaraf
New Member

Hi all,

Any idea what type of logs we can onboard for WSL2 and how we can do that.

Labels (2)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @mdmosaraf 

There is no official Splunk docs supporting WSL, however this link having some discussion around it which is about installing Splunk Enterprise. IS it possible to install Splunk on Ubuntu on Wind... - Splunk Community

If your requirement is to monitor WSL2 and Splunk Enterprise set-up is already running in your network in different host then i would give  a try installation of Splunk Universal Forwarder (UF), Linux version depends on 64/32 bit of your WLS2 OS. If that is successful then add-on Splunk Add-on for Unix and Linux | Splunkbase helps to extract some useful logs from Linux which will be installed on top of  UF.

Note: This is not official as per docs just a trail and test, Splunk might not support if you find issues with it. This may result into your WSL2 performance degradation as well if you are running critical apps just keep it in mind.

-------------------------------------------------------------

An upvote would be appreciated if it helps!

Tags (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...